QID 982605

QID 982605: Python (pip) Security Update for django (GHSA-h5jv-4p7w-64jg)

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large sequences of nested incomplete HTML entities.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-h5jv-4p7w-64jg for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982605

    Software Advisories
    Advisory ID Software Component Link
    GHSA-h5jv-4p7w-64jg django URL Logo github.com/advisories/GHSA-h5jv-4p7w-64jg