logo

CVE-2011-4137 django

Package

Manager: pip
Name: django
Vulnerable Version: >=0 <1.2.7 || >=1.3 <1.3.1

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.01736 pctl0.81749

Details

Denial of service in django The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which allows remote attackers to cause a denial of service (resource consumption) via a URL associated with (1) a slow response, (2) a completed TCP connection with no application data sent, or (3) a large amount of application data, a related issue to CVE-2011-1521.

Metadata

Created: 2018-07-23T19:51:35Z
Modified: 2024-09-16T22:34:20Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-3jqw-crqj-w8qw/GHSA-3jqw-crqj-w8qw.json
CWE IDs: ["CWE-1088"]
Alternative ID: GHSA-3jqw-crqj-w8qw
Finding: F138
Auto approve: 1