Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2024-38875
HistoryJul 10, 2024 - 12:00 a.m.

CVE-2024-38875

2024-07-1000:00:00
mitre
github.com
2
django
denial of service
brackets
cve-2024-38875

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:djangoproject:django:4.2:-:*:*:*:*:*:*"
    ],
    "vendor": "djangoproject",
    "product": "django",
    "versions": [
      {
        "status": "affected",
        "version": "4.2",
        "lessThan": "4.2.14",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:djangoproject:django:5.0:*:*:*:*:*:*:*"
    ],
    "vendor": "djangoproject",
    "product": "django",
    "versions": [
      {
        "status": "affected",
        "version": "5.0",
        "lessThan": "5.0.7",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial