Vulnerability CVE-2024-24680: Information

Description

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Feb. 7, 2024
Modified: April 20, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
python3-module-djangosisyphus4.2.11-alt14.2.11-alt1ALT-PU-2024-4472-2343297Fixed
python3-module-djangosisyphus_e2k4.2.11-alt14.2.11-alt1ALT-PU-2024-4587-1-Fixed
python3-module-djangosisyphus_riscv644.2.11-alt14.2.11-alt1ALT-PU-2024-4668-1-Fixed
python3-module-djangosisyphus_loongarch644.2.11-alt14.2.11-alt1ALT-PU-2024-4593-1-Fixed
python3-module-djangoc10f13.2.25-alt13.2.25-alt1ALT-PU-2024-3676-2342286Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      5.0
      End excliding
      5.0.2

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      3.2
      End excliding
      3.2.24

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      4.2
      End excliding
      4.2.10