Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0037 | An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters. |
Github GHSA |
GHSA-5hgc-2vfp-mqvc | Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filters |
Ubuntu USN |
USN-6987-1 | Django vulnerabilities |
Wed, 30 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| Metrics |
ssvc
|
ssvc
|
Tue, 29 Oct 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.5::el8 cpe:/a:redhat:ansible_automation_platform:2.5::el9 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
Sat, 19 Oct 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Djangoproject
Djangoproject django |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* cpe:2.3:a:djangoproject:django:5.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Djangoproject
Djangoproject django |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 08 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Python's Django urlize() and urlizetrunc() functions. Excessive input with a specific sequence of characters may lead to denial of service. | An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters. |
| References |
|
Wed, 25 Sep 2024 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in Python's Django urlize() and urlizetrunc() functions. Excessive input with a specific sequence of characters may lead to denial of service. |
Tue, 24 Sep 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | python-django: Potential denial-of-service vulnerability in django.utils.html.urlize() | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-17T14:12:05.808Z
Reserved: 2024-08-24T00:00:00.000Z
Link: CVE-2024-45230
Updated: 2024-10-08T18:34:21.663Z
Status : Modified
Published: 2024-10-08T16:15:11.903
Modified: 2025-03-17T15:15:41.520
Link: CVE-2024-45230
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN