USN-7136-1: Django vulnerabilities
jiangniao discovered that Django incorrectly handled the API to strip tags. A remote attacker could possibly use this issue to cause Django to consume resources, leading to a denial of service. (CVE-2024-53907) Seokchan Yoon discovered that Django incorrectly handled HasKey lookups when using Oracle. A remote attacker could possibly use this issue to inject arbitrary SQL code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-53908)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7136-1?
The USN-7136-1 vulnerability has the potential to lead to a denial of service due to resource exhaustion.
How do I fix USN-7136-1?
To fix USN-7136-1, you need to update the affected python3-django package to the recommended versions for your specific Ubuntu release.
Which versions of Django are affected by USN-7136-1?
USN-7136-1 affects Django versions before 3:4.2.15-1ubuntu1.1, 3:4.2.11-1ubuntu1.4, 2:3.2.12-2ubuntu1.15, and 2:2.2.12-1ubuntu0.26.
Who discovered the vulnerabilities in USN-7136-1?
The vulnerabilities addressed in USN-7136-1 were discovered by jiangniao and Seokchan Yoon.
Can USN-7136-1 be exploited remotely?
Yes, a remote attacker could exploit the USN-7136-1 vulnerability to cause Django to consume excessive resources.