First published: Fri Aug 02 2024(Updated: )
Description: urlize, urlizetrunc, and AdminURLFieldWidget were subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters. Affected versions ================= * Django main development branch * Django 5.1 (currently at release candidate status) * Django 5.0 * Django 4.2
Affected Software | Affected Version | How to fix |
---|---|---|
Django | <5.1 | |
Django |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2302435 has been classified as a potential denial-of-service vulnerability.
To fix REDHAT-BUG-2302435, upgrade to a patched version of Django that addresses this vulnerability.
REDHAT-BUG-2302435 affects the Django main development branch and versions up to but not including 5.1.
The vulnerability involves the urlize, urlizetrunc, and AdminURLFieldWidget components of Django.
Yes, there is a risk of exploitation that could lead to denial-of-service attacks using specially crafted inputs.