REDHAT-BUG-2302435: Medium severity Django Software Foundation Django vulnerability
Description: urlize, urlizetrunc, and AdminURLFieldWidget were subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.
Affected versions =================
Django main development branch Django 5.1 (currently at release candidate status) Django 5.0 Django 4.2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2302435?
REDHAT-BUG-2302435 has been classified as a potential denial-of-service vulnerability.
How do I fix REDHAT-BUG-2302435?
To fix REDHAT-BUG-2302435, upgrade to a patched version of Django that addresses this vulnerability.
Which versions of Django are affected by REDHAT-BUG-2302435?
REDHAT-BUG-2302435 affects the Django main development branch and versions up to but not including 5.1.
What components are involved in REDHAT-BUG-2302435?
The vulnerability involves the urlize, urlizetrunc, and AdminURLFieldWidget components of Django.
Is there a risk of exploitation with REDHAT-BUG-2302435?
Yes, there is a risk of exploitation that could lead to denial-of-service attacks using specially crafted inputs.