CVE Vulnerabilities

CVE-2024-45230

Published: Oct 08, 2024 | Modified: Mar 17, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

Affected Software

NameVendorStart VersionEnd Version
DjangoDjangoproject4.2.0 (including)4.2.16 (excluding)
DjangoDjangoproject5.0 (including)5.0.9 (excluding)
DjangoDjangoproject5.1 (including)5.1 (including)
Red Hat Ansible Automation Platform 2.5 for RHEL 8RedHatautomation-controller-0:4.6.2-1.el8ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 9RedHatautomation-controller-0:4.6.2-1.el9ap*
Python-djangoUbuntudevel*
Python-djangoUbuntuesm-infra/bionic*
Python-djangoUbuntuesm-infra/focal*
Python-djangoUbuntufocal*
Python-djangoUbuntujammy*
Python-djangoUbuntunoble*
Python-djangoUbuntuoracular*
Python-djangoUbuntuplucky*
Python-djangoUbuntuquesting*
Python-djangoUbuntutrusty/esm*

References