REDHAT-BUG-2418366: High severity pypi/django vulnerability
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in django.core.serializers.xmlserializer.getInnerText() allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion via specially crafted XML input processed by the XML Deserializer. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2418366?
REDHAT-BUG-2418366 is categorized as a potential denial-of-service vulnerability that can lead to CPU and memory exhaustion.
How do I fix REDHAT-BUG-2418366?
To fix REDHAT-BUG-2418366, upgrade to Django versions 5.2.9, 5.1.15, or 4.2.27 or later.
What versions of Django are affected by REDHAT-BUG-2418366?
Django versions before 5.2.9, 5.1.15, and 4.2.27 are affected by REDHAT-BUG-2418366.
What type of attack does REDHAT-BUG-2418366 enable?
REDHAT-BUG-2418366 enables a remote attacker to conduct a denial-of-service attack.
Is REDHAT-BUG-2418366 a remote vulnerability?
Yes, REDHAT-BUG-2418366 allows for a remote attacker to exploit the vulnerability.