Fiche vulnérabilité
CVE-2024-41989 : faille élevée djangoproject django (CVSS 7.5)
Description
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 août 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- djangoproject django