https://seclists.org/oss-sec/2024/q1/185: Django: CVE-2024-27351: Potential regular expression denial-of-service in django.utils.text.Truncator.words()
Published Mar 4, 2024
·Updated
Affected Software
1 affected component
Django Django
Frequently Asked Questions
1
What is the severity of CVE-2024-27351?
CVE-2024-27351 has been classified as a moderate severity vulnerability.
2
What is CVE-2024-27351 about?
CVE-2024-27351 is a potential regular expression denial-of-service vulnerability in the django.utils.text.Truncator.words() function.
3
How do I fix CVE-2024-27351?
To mitigate CVE-2024-27351, upgrade to the latest version of Django where the issue has been addressed.
4
Is CVE-2024-27351 exploitable for all users?
CVE-2024-27351 may be exploited by users who can manipulate input to the Truncator.words() function.
5
Which versions of Django are affected by CVE-2024-27351?
Django versions prior to the fix implemented on March 4, 2024, are affected by CVE-2024-27351.