cbcvebase.
CVE-2020-15225
published 2021-04-29

CVE-2020-15225: django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated…

PriorityP334medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.80%
76.0th percentile
django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input using exponential format with sufficiently large exponents. Version 2.4.0+ applies a `MaxValueValidator` with a a default `limit_value` of 1e50 to the form field used by `NumberFilter` instances. In addition, `NumberFilter` implements the new `get_max_validator()` which should return a configured validator instance to customise the limit, or else `None` to disable the additional validation. Users may manually apply an equivalent validator if they are not able to upgrade.

Affected

10 ranges
VendorProductVersion rangeFixed in
carltongibsondjango-filter< 2.4.02.4.0
debiandjango-filter< django-filter 2.4.0-1 (bookworm)django-filter 2.4.0-1 (bookworm)
django-filter_projectdjango-filter< 2.4.02.4.0
django-filter_projectdjango-filter>= 0 < 2.4.0-12.4.0-1
django-filter_projectdjango-filter>= 0 < 2.4.0-12.4.0-1
django-filter_projectdjango-filter>= 0 < 2.4.0-12.4.0-1
django-filter_projectdjango-filter>= 0 < 2.4.0-12.4.0-1
django-filter_projectdjango-filter>= 0 < 2.4.02.4.0
fedoraprojectfedora
fedoraprojectfedora

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.