Lucene search

K
ubuntuUbuntuUSN-6674-1
HistoryMar 04, 2024 - 12:00 a.m.

Django vulnerability

2024-03-0400:00:00
ubuntu.com
16
ubuntu
python-django
truncator function
denial of service

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%

Releases

  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • python-django - High-level Python web development framework

Details

Seokchan Yoon discovered that the Django Truncator function incorrectly
handled very long HTML input. A remote attacker could possibly use this
issue to cause Django to consume resources, leading to a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu23.10noarchpython3-django< 3:4.2.4-1ubuntu2.2UNKNOWN
Ubuntu23.10noarchpython-django-doc< 3:4.2.4-1ubuntu2.2UNKNOWN
Ubuntu22.04noarchpython3-django< 2:3.2.12-2ubuntu1.11UNKNOWN
Ubuntu22.04noarchpython-django-doc< 2:3.2.12-2ubuntu1.11UNKNOWN
Ubuntu20.04noarchpython3-django< 2:2.2.12-1ubuntu0.22UNKNOWN
Ubuntu20.04noarchpython-django-doc< 2:2.2.12-1ubuntu0.22UNKNOWN

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%