CVE-2024-24680: Django CVE-2024-24680: Potential denial-of-service in intcomma template filter
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
Other sources
The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
Refer: https://www.djangoproject.com/security/
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/python-djangoto a version that resolves this vulnerability.Fixed in 3:4.2.11-1 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 1:1.11.11-1ubuntu1.21+ - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 2:2.2.12-1ubuntu0.21 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 2:3.2.12-2ubuntu1.10 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 3:4.2.4-1ubuntu2.1 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 4.2.10Fixed in 3.2.24 - Upgrade
Upgrade
pip/Djangoto a version that resolves this vulnerability.Fixed in 3.2.24 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 5.0.2 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 4.2.10 - Upgrade
Upgrade
redhat/djangoto a version that resolves this vulnerability.Fixed in 3.2.24 - Upgrade
Upgrade
redhat/djangoto a version that resolves this vulnerability.Fixed in 4.2.10 - Upgrade
Upgrade
redhat/djangoto a version that resolves this vulnerability.Fixed in 5.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24680?
CVE-2024-24680 is classified as a potential denial-of-service vulnerability in Django.
How do I fix CVE-2024-24680?
To remediate CVE-2024-24680, upgrade Django to versions 3.2.24, 4.2.10, or 5.0.2 or later.
Which Django versions are affected by CVE-2024-24680?
The affected versions include Django 3.2 before 3.2.24, 4.2 before 4.2.10, and 5.0 before 5.0.2.
Can I upgrade Django using pip to fix CVE-2024-24680?
Yes, you can upgrade Django using pip to version 3.2.24, 4.2.10, or 5.0.2 to address CVE-2024-24680.
What impact does CVE-2024-24680 have on web applications?
CVE-2024-24680 may allow an attacker to cause a denial-of-service condition through the intcomma template filter.