VDB

CVE-2024-45230

CVE-2024-45230 PUBLISHED

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

EPSS 2.25% · 84.9th percentile

Risk Scores

EPSS Score
2.25%
84.9th percentile

Affected Products

VendorProductVersions
Bitnamidjango4.2.0, 5.1.0, 5.1.0
Bitnamidjango5.0.0, 5.1.0, 4.2.0

Timeline

  • CVE Published
  • Oct 9, 2024 EPSS Score
  • Oct 14, 2024 Coalition ESS Score
  • Oct 19, 2024 Coalition ESS Score
  • Oct 28, 2024 EPSS Score
  • Oct 30, 2024 Coalition ESS Score
  • Dec 6, 2024 EPSS Score
  • Dec 24, 2024 EPSS Score
  • Jan 31, 2025 EPSS Score
  • Feb 5, 2025 PoC Published
  • Feb 19, 2025 EPSS Score
  • Mar 9, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›