Skip to content

Commit

Permalink
Assign IDs
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions committed Jan 14, 2025
1 parent 7e6e070 commit 82bbc2e
Show file tree
Hide file tree
Showing 2 changed files with 22 additions and 22 deletions.
2 changes: 1 addition & 1 deletion vulns/.id-allocator
Original file line number Diff line number Diff line change
@@ -1 +1 @@
4307cb4f84d0150d15fb29543443cad9b87f1edc2a48c840f74d0e8775148fdd
790fdd56180984d5d1437ff1f474ab259f2c667ea80951ef8fdc2e88cb46dadd
Original file line number Diff line number Diff line change
@@ -1,39 +1,30 @@
id: PYSEC-0000-CVE-2024-56374
id: PYSEC-2025-1
modified: 2025-01-14T21:22:18.665005Z
published: 2025-01-14T19:15:32Z
aliases:
- CVE-2024-56374
details: An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and
4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when
performing IPv6 validation could lead to a potential denial-of-service attack. The
undocumented and private functions clean_ipv6_address and is_valid_ipv6_address
are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField
model field is not affected.)
aliases:
- CVE-2024-56374
modified: '2025-01-14T21:22:18.665005Z'
published: '2025-01-14T19:15:32Z'
references:
- type: ARTICLE
url: https://www.djangoproject.com/weblog/2025/jan/14/security-releases/
- type: WEB
url: https://docs.djangoproject.com/en/dev/releases/security/
- type: WEB
url: https://groups.google.com/g/django-announce
- type: WEB
url: http://www.openwall.com/lists/oss-security/2025/01/14/2
affected:
- package:
name: django
ecosystem: PyPI
name: django
purl: pkg:pypi/django
ranges:
- type: ECOSYSTEM
events:
- introduced: '5.1'
- introduced: "5.1"
- fixed: 5.1.5
- introduced: '5.0'
- introduced: "5.0"
- fixed: 5.0.11
- introduced: '4.2'
- introduced: "4.2"
- fixed: 4.2.18
versions:
- '4.2'
- "4.2"
- 4.2.1
- 4.2.10
- 4.2.11
Expand All @@ -51,7 +42,7 @@ affected:
- 4.2.7
- 4.2.8
- 4.2.9
- '5.0'
- "5.0"
- 5.0.1
- 5.0.10
- 5.0.2
Expand All @@ -62,8 +53,17 @@ affected:
- 5.0.7
- 5.0.8
- 5.0.9
- '5.1'
- "5.1"
- 5.1.1
- 5.1.2
- 5.1.3
- 5.1.4
references:
- type: ARTICLE
url: https://www.djangoproject.com/weblog/2025/jan/14/security-releases/
- type: WEB
url: https://docs.djangoproject.com/en/dev/releases/security/
- type: WEB
url: https://groups.google.com/g/django-announce
- type: WEB
url: http://www.openwall.com/lists/oss-security/2025/01/14/2

0 comments on commit 82bbc2e

Please sign in to comment.