CVE-2009-3695 – django
Package
Manager: pip
Name: django
Vulnerable Version: >=1.0 <1.0.4 || >=1.1 <1.1.1
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.06201 pctl0.90488
Details
Django Regex Algorithmic Complexity Causes Denial of Service Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.
Metadata
Created: 2022-05-02T03:47:43Z
Modified: 2024-09-16T21:57:14Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p6m5-h7pp-v2x5/GHSA-p6m5-h7pp-v2x5.json
CWE IDs: ["CWE-1333", "CWE-400"]
Alternative ID: GHSA-p6m5-h7pp-v2x5
Finding: F211
Auto approve: 1