• CVE-2024-56374

发布时间: 2025年1月24日

修改时间: 2025年1月24日

概要

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

CVSS v3 指标

NVD openEuler
Confidentiality None
Attack Vector Network
CVSS评分 N/A 5.8
Attack Complexity Low
Privileges Required None
Scope Changed
Integrity None
User Interaction None
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2367 python-django security update 2025年4月27日

影响产品

产品 状态
KY3.4-5 python-django Fixed
KY3.5.3 python-django Fixed
V6 python-django Fixed