Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.151100
Categoría:Denial of Service
Título:Django < 3.2.22, 4.1.x < 4.1.12, 4.2.x < 4.2.6 DoS Vulnerability - Linux
Resumen:Django is prone to a denial of service (DoS) vulnerability in; django.utils.text.Truncator.
Descripción:Summary:
Django is prone to a denial of service (DoS) vulnerability in
django.utils.text.Truncator.

Vulnerability Insight:
Following the fix for CVE-2019-14232, the regular expressions
used in the implementation of django.utils.text.Truncator's chars() and words() methods (with
html=True) were revised and improved. However, these regular expressions still exhibited linear
backtracking complexity, so when given a very long, potentially malformed HTML input, the
evaluation would still be slow, leading to a potential denial of service vulnerability.

Affected Software/OS:
Django prior to version 3.2.22, version 4.1.x prior through
4.1.11 and 4.2.x through 4.2.5.

Solution:
Update to version 3.2.22, 4.1.12, 4.2.6 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2023-43665
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HJFRPUHDYJHBH3KYHSPGULQM4JN7BMSU/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D/
https://docs.djangoproject.com/en/4.2/releases/security/
https://groups.google.com/forum/#!forum/django-announce
http://www.openwall.com/lists/oss-security/2024/03/04/1
CopyrightCopyright (C) 2023 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.