CVE-2015-0222: High severity ubuntu vulnerability
Published Jan 16, 2015
·Updated
ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when showhiddeninitial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
Affected Software
20 affected componentsFixes available
pip/Django>=1.7<1.7.3
1.7.3
pip/Django>=1.6<1.6.10
1.6.10
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
djangoproject Django<=1.4.17
djangoproject Django=1.6
djangoproject Django=1.6.1
djangoproject Django=1.6.2
djangoproject Django=1.6.3
djangoproject Django=1.6.4
djangoproject Django=1.6.5
djangoproject Django=1.6.6
djangoproject Django=1.6.7
djangoproject Django=1.6.8
djangoproject Django=1.6.9
djangoproject Django=1.7
djangoproject Django=1.7.1
djangoproject Django=1.7.2
Remediation
Patch Available
Patch Available
Event History
Jan 16, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:20 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-0222?
CVE-2015-0222 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2015-0222?
To fix CVE-2015-0222, upgrade Django to version 1.6.10 or later, or to version 1.7.3 or later.
3
What systems are affected by CVE-2015-0222?
CVE-2015-0222 affects Django versions 1.6.x before 1.6.10 and 1.7.x before 1.7.3.
4
What kind of attacks can exploit CVE-2015-0222?
CVE-2015-0222 can be exploited by remote attackers who submit duplicate values, which can lead to denial of service.
5
Is CVE-2015-0222 present in my Django installation?
You can check for CVE-2015-0222 by verifying your Django version is below 1.6.10 or 1.7.3.