CVE-2024-41991 Information

Description

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters and the AdminURLFieldWidget widget are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

https://docs.djangoproject.com/en/dev/releases/security/ https://groups.google.com/forum/#%21forum/django-announce https://www.djangoproject.com/weblog/2024/aug/06/security-releases/ An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters and the AdminURLFieldWidget widget are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

7.5

Share on: