CVE-2024-24680: Django CVE-2024-24680: Potential denial-of-service in intcomma template filter

Published Jan 30, 2024
·
Updated

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

Other sources

The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

Refer: https://www.djangoproject.com/security/

Red Hat

Affected Software

15 affected componentsFixes available
debian/python-django<=1:1.11.29-1~deb10u1, <=1:1.11.29-1+deb10u11, <=2:2.2.28-1~deb11u2, <=3:3.2.19-1+deb12u1
3:4.2.11-1
ubuntu/python-django<1:1.11.11-1ubuntu1.21+
1:1.11.11-1ubuntu1.21+
ubuntu/python-django<2:2.2.12-1ubuntu0.21
2:2.2.12-1ubuntu0.21
ubuntu/python-django<2:3.2.12-2ubuntu1.10
2:3.2.12-2ubuntu1.10
ubuntu/python-django<3:4.2.4-1ubuntu2.1
3:4.2.4-1ubuntu2.1
ubuntu/python-django<4.2.10, <3.2.24
4.2.103.2.24
pip/Django>=3.2<3.2.24
3.2.24
pip/django>=5.0<5.0.2
5.0.2
pip/django>=4.2<4.2.10
4.2.10
djangoproject Django>=3.2<3.2.24
djangoproject Django>=4.2<4.2.10
djangoproject Django>=5.0<5.0.2
redhat/django<3.2.24
3.2.24
redhat/django<4.2.10
4.2.10
redhat/django<5.0.2
5.0.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/python-django to a version that resolves this vulnerability.

    Fixed in 3:4.2.11-1
  2. Upgrade

    Upgrade ubuntu/python-django to a version that resolves this vulnerability.

    Fixed in 1:1.11.11-1ubuntu1.21+
  3. Upgrade

    Upgrade ubuntu/python-django to a version that resolves this vulnerability.

    Fixed in 2:2.2.12-1ubuntu0.21
  4. Upgrade

    Upgrade ubuntu/python-django to a version that resolves this vulnerability.

    Fixed in 2:3.2.12-2ubuntu1.10
  5. Upgrade

    Upgrade ubuntu/python-django to a version that resolves this vulnerability.

    Fixed in 3:4.2.4-1ubuntu2.1
  6. Upgrade

    Upgrade ubuntu/python-django to a version that resolves this vulnerability.

    Fixed in 4.2.10Fixed in 3.2.24
  7. Upgrade

    Upgrade pip/Django to a version that resolves this vulnerability.

    Fixed in 3.2.24
  8. Upgrade

    Upgrade pip/django to a version that resolves this vulnerability.

    Fixed in 5.0.2
  9. Upgrade

    Upgrade pip/django to a version that resolves this vulnerability.

    Fixed in 4.2.10
  10. Upgrade

    Upgrade redhat/django to a version that resolves this vulnerability.

    Fixed in 3.2.24
  11. Upgrade

    Upgrade redhat/django to a version that resolves this vulnerability.

    Fixed in 4.2.10
  12. Upgrade

    Upgrade redhat/django to a version that resolves this vulnerability.

    Fixed in 5.0.2

Event History

Jan 30, 2024
Data Sourced
via Red Hat·06:41 AM
DescriptionSeverityAffected Software
Feb 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityAffected Software
Feb 7, 2024
Advisory Published
via GitHub·12:30 AM
Feb 14, 2024
Data Sourced
via Launchpad·05:14 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2024-24680?

CVE-2024-24680 is classified as a potential denial-of-service vulnerability in Django.

2

How do I fix CVE-2024-24680?

To remediate CVE-2024-24680, upgrade Django to versions 3.2.24, 4.2.10, or 5.0.2 or later.

3

Which Django versions are affected by CVE-2024-24680?

The affected versions include Django 3.2 before 3.2.24, 4.2 before 4.2.10, and 5.0 before 5.0.2.

4

Can I upgrade Django using pip to fix CVE-2024-24680?

Yes, you can upgrade Django using pip to version 3.2.24, 4.2.10, or 5.0.2 to address CVE-2024-24680.

5

What impact does CVE-2024-24680 have on web applications?

CVE-2024-24680 may allow an attacker to cause a denial-of-service condition through the intcomma template filter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203