Resource exhaustion in Django - CVE-2024-53907
Published: December 5, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the django.utils.html.strip_tags() function. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Oracle Solaris
Storage Defender - Resiliency Service
Maximo Application Suite - Edge Data Collector
python-django (Ubuntu package)
python3-django (Ubuntu package)
python3.11-galaxy-importer (Red Hat package)
automation-eda-controller (Red Hat package)
python3.11-yarl (Red Hat package)
python-django
python-django-help
python3-Django
python3.11-aiohappyeyeballs (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
python3.11-django-ansible-base (Red Hat package)
automation-gateway (Red Hat package)
ansible-core (Red Hat package)
python3.11-jinja2 (Red Hat package)
python3.11-aiodns (Red Hat package)
python-django (Debian package)
python3.11-aiohttp (Red Hat package)
python3.11-pulpcore (Red Hat package)
python311-Django
python3-django-doc
python3-django-bash-completion
python3-django
python3.11-django (Red Hat package)
automation-controller (Red Hat package)
dev-python/django
Ansible Automation Platform
How to mitigate CVE-2024-53907
Storage Defender - Resiliency Service - update to 2.0.11
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.14, 9.0.6, 9.1.0
python-django (Ubuntu package) - update to Ubuntu Pro
python3-django (Ubuntu package) - addressed in versions Ubuntu Pro, 2:2.2.12-1ubuntu0.26, 2:3.2.12-2ubuntu1.15, 3:4.2.11-1ubuntu1.4, 3:4.2.15-1ubuntu1.1
python3.11-galaxy-importer (Red Hat package) - addressed in versions 0.4.27-1.el8ap, 0.4.27-1.el9ap
automation-eda-controller (Red Hat package) - addressed in versions 1.1.4-1.el8ap, 1.1.4-1.el9ap
python3.11-yarl (Red Hat package) - addressed in versions 1.13.1-1.el8ap, 1.13.1-1.el9ap
python-django - addressed in versions 2.2.27-13, 4.2.15-3
python-django-help - addressed in versions 2.2.27-13, 4.2.15-3
python3-Django - addressed in versions 2.2.27-13, 4.2.15-3
Ansible Automation Platform - addressed in versions 2.4, 2.5
python3.11-aiohappyeyeballs (Red Hat package) - addressed in versions 2.4.4-1.el8ap, 2.4.4-1.el9ap
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.5-7.el8ap, 2.5-7.el9ap, 2.5-8.el8ap, 2.5-8.el9ap
python3.11-django-ansible-base (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
automation-gateway (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.16.14-2.el8ap, 2.16.14-2.el9ap
python3.11-jinja2 (Red Hat package) - addressed in versions 3.1.5-1.el8ap, 3.1.5-1.el9ap
python3.11-aiodns (Red Hat package) - addressed in versions 3.2.0-1.el8ap, 3.2.0-1.el9ap
python-django (Debian package) - update to 3:3.2.25-0+deb12u1
python3.11-aiohttp (Red Hat package) - addressed in versions 3.10.11-1.el8ap, 3.10.11-1.el9ap
python3.11-pulpcore (Red Hat package) - addressed in versions 3.49.29-1.el8ap, 3.49.29-1.el9ap, 3.49.30-1.el8ap, 3.49.30-1.el9ap
python311-Django - update to 4.2.11-150600.3.12.1
python3-django-doc - update to 4.2.16-2
python3-django-bash-completion - update to 4.2.16-2
python3-django - update to 4.2.16-2
python3.11-django (Red Hat package) - addressed in versions 4.2.18-1.el8ap, 4.2.18-1.el9ap
automation-controller (Red Hat package) - addressed in versions 4.6.6-1.el8ap, 4.6.6-1.el9ap, 4.6.7-1.el8ap, 4.6.7-1.el9ap
dev-python/django - update to 5.2.1
Oracle Solaris - update to 11.4 SRU 77
External References
Related Security Bulletins
- Multiple vulnerabilities in Django
- Ubuntu update for python-django
- Ubuntu update for python-django
- SUSE update for python-Django
- openEuler 22.03 LTS SP1 update for python-django
- openEuler 20.03 LTS SP4 update for python-django
- openEuler 22.03 LTS SP3 update for python-django
- openEuler 22.03 LTS SP4 update for python-django
- openEuler 24.03 LTS update for python-django
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Oracle Solaris update for third-party components
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Multiple vulnerabilities in IBM Edge Data Collector
- Anolis OS update for python-django
- Gentoo update for Django
- Debian update for python-django