CVE-2019-6975: High severity djangoproject Django vulnerability
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
Other sources
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6975?
The severity of CVE-2019-6975 is high with a CVSS score of 7.5.
How does CVE-2019-6975 affect Django?
CVE-2019-6975 affects Django versions 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6.
What is the vulnerability description of CVE-2019-6975?
CVE-2019-6975 allows uncontrolled memory consumption in Django via a malicious attacker-supplied value to the `django.utils.numberformat.format()` function.
How can I fix CVE-2019-6975 on Django?
To fix CVE-2019-6975 on Django, you should upgrade to version 1.11.19, 2.0.11, or 2.1.6, depending on the affected version.
Where can I find more information about CVE-2019-6975?
You can find more information about CVE-2019-6975 on the NIST website (https://nvd.nist.gov/vuln/detail/CVE-2019-6975), the Django security releases (https://docs.djangoproject.com/en/dev/releases/security/), and the Django-announce Google Group (https://groups.google.com/forum/#!topic/django-announce/WTwEAprR0IQ).