python-django: Potential denial-of-service vulnerability in django.utils.html.urlize()
Published Aug 7, 2024
6.9
MEDIUMCVSS 4.0
EPSS 1.26%
Description
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
Affected products
No data.
- ≥ 4.2 · < 4.2.15
- ≥ 5.0 · < 5.0.8
-
- Version 4.2StatusaffectedConstraints<4.2.15
- Version 5.0StatusaffectedConstraints<5.0.8
- Version pkg:pypi/django@4.2StatusaffectedConstraints<pkg:pypi/django@4.2.15
- Version pkg:pypi/django@5.0StatusaffectedConstraints<pkg:pypi/django@5.0.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Djangoproject | Django | n/a |
|
RHUI 4 for RHEL 8
python-django-0:4.2.15-1.el8ui
Fixed · RHSA-2025:1335
Red Hat Ansible Automation Platform 2.4 for RHEL 8
automation-controller-0:4.5.10-1.el8ap
Fixed · RHSA-2024:6428
Red Hat Ansible Automation Platform 2.4 for RHEL 8
python3x-django-0:4.2.15-1.el8ap
Fixed · RHSA-2024:6428
Red Hat Ansible Automation Platform 2.4 for RHEL 9
automation-controller-0:4.5.10-1.el9ap
Fixed · RHSA-2024:6428
Red Hat Ansible Automation Platform 2.4 for RHEL 9
python-django-0:4.2.15-1.el9ap
Fixed · RHSA-2024:6428
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/ee-dellemc-openmanage-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/platform-resource-runner-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/lightspeed-rhel8
Not affected
Red Hat Certification Program for Red Hat Enterprise Linux 9
redhat-certification
Not affected
Red Hat Certification for Red Hat Enterprise Linux 8
redhat-certification
Not affected
Red Hat Discovery 1
discovery-server-container
Affected
Red Hat Satellite 6
python-django
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHUI 4 for RHEL 8 | python-django-0:4.2.15-1.el8ui | Fixed | RHSA-2025:1335 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | automation-controller-0:4.5.10-1.el8ap | Fixed | RHSA-2024:6428 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | python3x-django-0:4.2.15-1.el8ap | Fixed | RHSA-2024:6428 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | automation-controller-0:4.5.10-1.el9ap | Fixed | RHSA-2024:6428 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | python-django-0:4.2.15-1.el9ap | Fixed | RHSA-2024:6428 |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/ee-dellemc-openmanage-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/platform-resource-runner-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-rhel8 | Not affected | n/a |
| Red Hat Certification Program for Red Hat Enterprise Linux 9 | redhat-certification | Not affected | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 8 | redhat-certification | Not affected | n/a |
| Red Hat Discovery 1 | discovery-server-container | Affected | n/a |
| Red Hat Satellite 6 | python-django | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Implementing input validation and limiting the the size of inputs to the urlize and urlizetrunc will mitigate this vulnerability.
References (13)
- https://access.redhat.com/security/cve/CVE-2024-41990 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2302434 Issue Tracking
- https://docs.djangoproject.com/en/dev/releases/security PatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0045 Advisory
- https://github.com/advisories/GHSA-795c-9xpc-xw6g Advisory
- https://github.com/django/django/commit/7b7b909579c8311c140c89b8a9431bf537febf93
- https://github.com/django/django/commit/d0a82e26a74940bf0c78204933c3bdd6a283eb88
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-68.yaml
- https://groups.google.com/forum/#%21forum/django-announce Not Applicable
- https://nvd.nist.gov/vuln/detail/CVE-2024-41990
- https://security.netapp.com/advisory/ntap-20240905-0007
- https://www.cve.org/CVERecord?id=CVE-2024-41990
- https://www.djangoproject.com/weblog/2024/aug/06/security-releases Vendor Advisory
Change history (0)
No recorded changes yet.