Back to search
CVE-2018-7536
Published: Mar 9, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-3591-1
vendor-advisory
RHSA-2019:0051
vendor-advisory
103361
vdb-entry
RHSA-2019:0082
vendor-advisory
RHSA-2018:2927
vendor-advisory
RHSA-2019:0265
vendor-advisory
DSA-4161
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now