CVE-2019-6975

Aliases:GHSA-wh4h-v3f2-r2ppPYSEC-2019-18
Modified
Published: 11 Feb 2019, 13:00
Last modified:04 Aug 2024, 20:38

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v3.0 (nvd)
EPSS Score
6.46% LOW
6% probability -0.93%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Feb 2019, 13:00
Published
Vulnerability first disclosed
04 Aug 2024, 20:38
Last Modified
Vulnerability information updated

Description

Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 6.46% Percentile: 91%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • canonicalubuntu_linux

    16.04 | 18.04 | 18.10

  • djangoprojectdjango

    ≥ 1.11.0, < 1.11.19 | ≥ 2.0.0, < 2.0.11 | ≥ 2.1.0, < 2.1.6

  • fedoraprojectfedora

    28 | 29

  • PyPIdjango

    ≥ 1.11, < 1.11.19 | ≥ 2.0, < 2.0.11 | ≥ 2.1, < 2.1.6 | ≥ 2.1, < 2.1.7

References (26)