VDB
CVE-2024-41991
CVE-2024-41991
PUBLISHED
CVSS 7.5 HIGH
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.
EPSS 0.95% · 59.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.95%
59.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | django | 4.2.0, 5.0.0, 4.2.0 |
| Bitnami | django | 5.0.0, 4.2.0 |
Timeline
- Aug 6, 2024 CVE Published
- Aug 13, 2024 EPSS Score
- Sep 3, 2024 EPSS Score
- Sep 25, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 16, 2024 EPSS Score
- Nov 7, 2024 EPSS Score
- Dec 20, 2024 EPSS Score
- Jan 11, 2025 EPSS Score
- Feb 1, 2025 EPSS Score
- Feb 2, 2025 Coalition ESS Score
- Feb 22, 2025 EPSS Score
References
- https://docs.djangoproject.com/en/dev/releases/security/ url
- https://groups.google.com/forum/#%21forum/django-announce url
- https://www.djangoproject.com/weblog/2024/aug/06/security-releases/ url
- https://nvd.nist.gov/vuln/detail/CVE-2024-41991 url
- https://security.netapp.com/advisory/ntap-20240905-0007/ url