Lucene search

K
ubuntuUbuntuUSN-6888-2
HistoryJul 11, 2024 - 12:00 a.m.

Django vulnerabilities

2024-07-1100:00:00
ubuntu.com
12
django
ubuntu 18.04
esm
denial of service
file path validation
timing attack
enumeration
storage class
arbitrary directories

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6

Confidence

High

Releases

  • Ubuntu 18.04 ESM

Packages

  • python-django - High-level Python web development framework

Details

USN-6888-1 fixed several vulnerabilities in Django. This update provides
the corresponding update for Ubuntu 18.04 LTS.

Original advisory details:

Elias Myllymรคki discovered that Django incorrectly handled certain inputs
with a large number of brackets. A remote attacker could possibly use this
issue to cause Django to consume resources or stop responding, resulting in
a denial of service. (CVE-2024-38875)

It was discovered that Django incorrectly handled authenticating users with
unusable passwords. A remote attacker could possibly use this issue to
perform a timing attack and enumerate users. (CVE-2024-39329)

Josh Schneier discovered that Django incorrectly handled file path
validation when the storage class is being derived. A remote attacker could
possibly use this issue to save files into arbitrary directories.
(CVE-2024-39330)

It was discovered that Django incorrectly handled certain long strings that
included a specific set of characters. A remote attacker could possibly use
this issue to cause Django to consume resources or stop responding,
resulting in a denial of service. (CVE-2024-39614)

OSVersionArchitecturePackageVersionFilename
Ubuntu18.04noarchpython-django<ย 1:1.11.11-1ubuntu1.21+esm5UNKNOWN
Ubuntu18.04noarchpython-django<ย 1:1.11.11-1ubuntu1.21UNKNOWN
Ubuntu18.04noarchpython-django-common<ย 1:1.11.11-1ubuntu1.21UNKNOWN
Ubuntu18.04noarchpython-django-doc<ย 1:1.11.11-1ubuntu1.21UNKNOWN
Ubuntu18.04noarchpython3-django<ย 1:1.11.11-1ubuntu1.21UNKNOWN
Ubuntu18.04noarchpython3-django<ย 1:1.11.11-1ubuntu1.21+esm5UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6

Confidence

High