Wind River Support Network

HomeDefectsLIN10-7431
Fixed

LIN10-7431 : Security Advisory - python3-django - CVE-2018-7536

Created: Jun 8, 2020    Updated: May 13, 2022
Resolved Date: Jun 11, 2020
Previous ID: LIN1018-6302
Found In Version: 10.17.41.20
Fix Version: 10.17.41.21
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.

CREATE(Triage):(User=admin) CVE-2018-7536 (https://nvd.nist.gov/vuln/detail/CVE-2018-7536)

CVEs


Live chat
Online