Description
ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
References (11)
Core 11
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148608.html
Patch, Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://ubuntu.com/usn/usn-2469-1
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148696.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/62285
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-09/msg00035.html
Patch, Vendor Advisory x_refsource_confirm
https://www.djangoproject.com/weblog/2015/jan/13/security/
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-04/msg00001.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/62309
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:109
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2015-0026.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148485.html
Scores
EPSS
0.0269
EPSS Percentile
84.2%
Details
CWE
CWE-17
Status
published
Products (19)
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
14.04
canonical/ubuntu_linux
14.10
djangoproject/django
1.6
djangoproject/django
1.6.1
djangoproject/django
1.6.2
djangoproject/django
1.6.3
djangoproject/django
1.6.4
djangoproject/django
1.6.5
... and 9 more
Published
Jan 16, 2015
Tracked Since
Feb 18, 2026