发布时间: 2025年1月24日
修改时间: 2025年1月24日
An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)
NVD | openEuler | |
---|---|---|
Confidentiality | None | |
Attack Vector | Network | |
CVSS评分 | N/A | 5.8 |
Attack Complexity | Low | |
Privileges Required | None | |
Scope | Changed | |
Integrity | None | |
User Interaction | None | |
Availability | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2025-2367 | python-django security update | 2025年4月27日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5 | python-django | Fixed |
KY3.5.3 | python-django | Fixed |
V6 | python-django | Fixed |