logo

CVE-2009-3695 django

Package

Manager: pip
Name: django
Vulnerable Version: >=1.0 <1.0.4 || >=1.1 <1.1.1

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.06201 pctl0.90488

Details

Django Regex Algorithmic Complexity Causes Denial of Service Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

Metadata

Created: 2022-05-02T03:47:43Z
Modified: 2024-09-16T21:57:14Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p6m5-h7pp-v2x5/GHSA-p6m5-h7pp-v2x5.json
CWE IDs: ["CWE-1333", "CWE-400"]
Alternative ID: GHSA-p6m5-h7pp-v2x5
Finding: F211
Auto approve: 1