7.5
CVSSv3

CVE-2023-43665

Published: 03/11/2023 Updated: 20/04/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In Django 3.2 prior to 3.2.22, 4.1 prior to 4.1.12, and 4.2 prior to 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which are thus also vulnerable. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232.

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django

fedoraproject fedora 39

Vendor Advisories

Synopsis Moderate: Red Hat Ansible Automation Platform 24 Product Security and Bug Fix Update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 24Red Hat P ...
Debian Bug report logs - #1053475 python-django: CVE-2023-43665: Denial-of-service possibility in djangoutilstextTruncator Package: src:python-django; Maintainer for src:python-django is Debian Python Team <team+python@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 4 Oct 2023 ...
Description<!---->An inefficient regular expression complexity was found in Django The text truncator regular expressions exhibit linear backtracking complexity, which can be slow, leading to a potential denial of service, given certain HTML inputsAn inefficient regular expression complexity was found in Django The text truncator regular express ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Django: CVE-2024-27351: Potential regular expression denial-of-service in djangoutilstextTruncatorwords() <!--X-Subject-He ...