CVE-2011-4137 – django
Package
Manager: pip
Name: django
Vulnerable Version: >=0 <1.2.7 || >=1.3 <1.3.1
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.01736 pctl0.81749
Details
Denial of service in django The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which allows remote attackers to cause a denial of service (resource consumption) via a URL associated with (1) a slow response, (2) a completed TCP connection with no application data sent, or (3) a large amount of application data, a related issue to CVE-2011-1521.
Metadata
Created: 2018-07-23T19:51:35Z
Modified: 2024-09-16T22:34:20Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-3jqw-crqj-w8qw/GHSA-3jqw-crqj-w8qw.json
CWE IDs: ["CWE-1088"]
Alternative ID: GHSA-3jqw-crqj-w8qw
Finding: F138
Auto approve: 1