7.5
CVSSv3

CVE-2019-14232

Published: 02/08/2019 Updated: 01/05/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Django 1.11.x prior to 1.11.23, 2.1.x prior to 2.1.11, and 2.2.x prior to 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which were thus vulnerable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django

opensuse leap 15.1

Vendor Advisories

Several security issues were fixed in Django ...
Debian Bug report logs - #934026 python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235 Package: python-django; Maintainer for python-django is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Source for python-django is src:python-django (PTS, buildd, popcon) Reported by: "Chris ...
Synopsis Moderate: python-django security update Type/Severity Security Advisory: Moderate Topic An update for python-django is now available for Red Hat OpenStack Platform15 (Stein)Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System ...
Synopsis Moderate: python-django security update Type/Severity Security Advisory: Moderate Topic An update for python-django is now available for Red Hat OpenStack Platform13 (Queens)Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System ...
Several vulnerabilities were discovered in python-django, a web development framework They could lead to remote denial-of-service or SQL injection, For the oldstable distribution (stretch), these problems have been fixed in version 1:1107-2+deb9u6 For the stable distribution (buster), these problems have been fixed in version 11123-1~deb10u1 ...
If ``djangoutilstextTruncator``'s ``chars()`` and ``words()`` methods were passed the ``html=True`` argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression The ``chars()`` and ``words()`` methods are used to implement the ``truncatechars_html`` and ``truncatewords_ht ...

Mailing Lists

Permalink: wwwdjangoprojectcom/weblog/2019/aug/01/security-releases/ In accordance with `our security release policy <docsdjangoprojectcom/en/dev/internals/security/>`_, the Django team is issuing `Django 11123 <docsdjangoprojectcom/en/dev/releases/11123/>`_, `Django 2111 <docsdjangopro ...
wwwdjangoprojectcom/weblog/2024/mar/04/security-releases/ In accordance with `our security release policy is issuing `Django 503 <docsdjangoprojectcom/en/dev/releases/503/>`_, `Django 3225 <docsdjangoprojectcom/en/dev/releases/3225/>`_ These releases addresses the security issue detailed below ...