VDB

CVE-2024-41991

CVE-2024-41991 PUBLISHED CVSS 7.5 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.

EPSS 0.95% · 59.8th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.95%
59.8th percentile

Affected Products

VendorProductVersions
Bitnamidjango4.2.0, 5.0.0, 4.2.0
Bitnamidjango5.0.0, 4.2.0

Timeline

  • Aug 6, 2024 CVE Published
  • Aug 13, 2024 EPSS Score
  • Sep 3, 2024 EPSS Score
  • Sep 25, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 16, 2024 EPSS Score
  • Nov 7, 2024 EPSS Score
  • Dec 20, 2024 EPSS Score
  • Jan 11, 2025 EPSS Score
  • Feb 1, 2025 EPSS Score
  • Feb 2, 2025 Coalition ESS Score
  • Feb 22, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›