CVE-2024-56374

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)
Configurations

No configuration.

History

23 Jan 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Django 5.1 antes de 5.1.5, 5.0 antes de 5.0.11 y 4.2 antes de 4.2.18. La falta de aplicación de un límite superior en las cadenas que se pasan al realizar la validación de IPv6 podría provocar un posible ataque de denegación de servicio. Las funciones privadas y no documentadas clean_ipv6_address e is_valid_ipv6_address son vulnerables, al igual que el campo de formulario django.forms.GenericIPAddressField. (El campo de modelo django.db.models.GenericIPAddressField no se ve afectado).
References
  • () https://lists.debian.org/debian-lts-announce/2025/01/msg00024.html -

14 Jan 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 19:15

Updated : 2025-01-23 18:15


NVD link : CVE-2024-56374

Mitre link : CVE-2024-56374

CVE.ORG link : CVE-2024-56374


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling