CVE-2024-24680High· 7.5▾ TwilightAn issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.6%
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
django >= 3.2, < 3.2.24django >= 4.2, < 4.2.10django >= 5.0, < 5.0.2Upgrade past the affected range:
django 5.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2024-39329Medium· 5.3An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14
CVE-2024-27351Medium· 5.3Regular expression denial-of-service in Django
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
CVE-2024-39614High· 7.5Django vulnerable to Denial of Service
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses