CVE-2015-5145: High severity django vulnerability
Published Jul 14, 2015
·Updated
validators.URLValidator in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
Other sources
validators.URLValidator in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
Affected Software
4 affected componentsFixes available
pip/Django>=1.8a1<1.8.3
1.8.3
djangoproject Django=1.8.0
djangoproject Django=1.8.1
djangoproject Django=1.8.2
Event History
Jul 14, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
May 17, 2022
Advisory Published
12:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-5145?
CVE-2015-5145 has a severity rating of moderate as it allows remote attackers to exhaust CPU resources, leading to a denial of service.
2
How do I fix CVE-2015-5145?
To fix CVE-2015-5145, you should upgrade Django to version 1.8.3 or later.
3
Which versions of Django are affected by CVE-2015-5145?
Django versions 1.8.0, 1.8.1, and 1.8.2 are affected by CVE-2015-5145.
4
What type of vulnerability is CVE-2015-5145?
CVE-2015-5145 is classified as a denial of service vulnerability.
5
Can CVE-2015-5145 be exploited remotely?
Yes, CVE-2015-5145 can be exploited remotely by attackers to cause CPU consumption.