CVE-2018-7536
Summary
| CVE | CVE-2018-7536 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-09 20:29:00 UTC |
| Updated | 2023-12-07 22:15:00 UTC |
| Description | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| github.com/django/django/commit/e157315da3ae7005fa0683ffc9751dbeca7306c8 |
|
github.com |
|
| github.com/django/django/commit/1ca63a66ef3163149ad822701273e8a1844192c2 |
|
github.com |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4161-1 python-django |
DEBIAN |
www.debian.org |
Third Party Advisory |
| github.com/django/django/commit/abf89d729f210c692a50e0ad3f75fb6bec6fae16 |
|
github.com |
|
| Django security releases issued: 2.0.3, 1.11.11, and 1.8.19 | Weblog | Django |
CONFIRM |
www.djangoproject.com |
Release Notes, Vendor Advisory |
| Django CVE-2018-7536 Multiple Denial of Service Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| USN-3591-1: Django vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] [DLA 1303-1] python-django security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500774 Alpine Linux Security Update for py3-django
- 981350 Python (pip) Security Update for django (GHSA-r28v-mw67-m5p9)