Django is vulnerable to regular expression denial of service (ReDoS). The attack is due to lack of validation of inputs to a regular expression in django.utils.text.Truncator
’s chars()
and words()
methods, eventually causing an application crash if the input html=True
is provided.
lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html
lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html
django.readthedocs.io/en/latest/releases/security.html
docs.djangoproject.com/en/dev/releases/security/
groups.google.com/forum/#!topic/django-announce/jIoju2-KLDs
lists.fedoraproject.org/archives/list/[email protected]/message/STVX7X7IDWAH5SKE6MBMY3TEI6ZODBTK/
seclists.org/bugtraq/2019/Aug/15
www.debian.org/security/2019/dsa-4498
www.djangoproject.com/weblog/2019/aug/01/security-releases/