CVE-2019-14232

HIGH

Django <1.11.23, 2.1.x <2.1.11, 2.2.x <2.2.4 - RCE

Title source: llm
STIX 2.1

Description

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which were thus vulnerable.

Scores

CVSS v3 7.5
EPSS 0.0297
EPSS Percentile 86.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (3)
djangoproject/django 1.11 - 1.11.23
opensuse/leap 15.1
pypi/Django 1.11a1 - 1.11.23PyPI
Published Aug 02, 2019
Tracked Since Feb 18, 2026