CVE-2024-28865
published 2024-03-18CVE-2024-28865: django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciously crafted article content that can…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.61%
47.8th percentile
django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciously crafted article content that can cause severe use of server CPU through a regular expression loop. Version 0.10.1 fixes this issue. As a workaround, close off access to create and edit articles by anonymous users.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| django-wiki | django-wiki | < 0.10.1 | 0.10.1 |
| django-wiki_project | django-wiki | < 0.10.1 | 0.10.1 |
| requarks | wiki | >= 0 < 0.10.1 | 0.10.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Denial of service via regular expression
osv·2024-03-18
CVE-2024-28865 [HIGH] Denial of service via regular expression
Denial of service via regular expression
### Impact
All historical installations of django-wiki are vulnerable to maliciously crafted article content, that can cause severe use of server CPU through a regular expression loop.
### Patches
### Workarounds
Close off access to create and edit articles by anonymous users.
### References
_Are there any links users can visit to find out more?_
GHSA
Denial of service via regular expression
ghsa·2024-03-18
CVE-2024-28865 [HIGH] CWE-1333 Denial of service via regular expression
Denial of service via regular expression
### Impact
All historical installations of django-wiki are vulnerable to maliciously crafted article content, that can cause severe use of server CPU through a regular expression loop.
### Patches
### Workarounds
Close off access to create and edit articles by anonymous users.
### References
_Are there any links users can visit to find out more?_
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/django-wiki/django-wiki/commit/8e280fd6c0bd27ce847c67b2d216c6cbf920f88chttps://github.com/django-wiki/django-wiki/security/advisories/GHSA-wj85-w4f4-xh8hhttps://github.com/django-wiki/django-wiki/commit/8e280fd6c0bd27ce847c67b2d216c6cbf920f88chttps://github.com/django-wiki/django-wiki/security/advisories/GHSA-wj85-w4f4-xh8h
2024-03-18
Published