Skip to content
This repository has been archived by the owner on May 22, 2024. It is now read-only.

[Snyk High] - django Denial of Service (DoS)(Due 03/15/2024) #833

Closed
1 task
fec-jli opened this issue Feb 14, 2024 · 0 comments · Fixed by #838
Closed
1 task

[Snyk High] - django Denial of Service (DoS)(Due 03/15/2024) #833

fec-jli opened this issue Feb 14, 2024 · 0 comments · Fixed by #838
Assignees
Labels
Pipeline: Ready Security: high Remediate within 30 days
Milestone

Comments

@fec-jli
Copy link
Contributor

fec-jli commented Feb 14, 2024

https://app.snyk.io/org/fecgov/project/5e01de94-91bc-43d8-90b1-8843384b4b26#issue-SNYK-PYTHON-DJANGO-6230369

Overview
Affected versions of this package are vulnerable to Denial of Service (DoS) in the intcomma template filter, when used with very long strings. Exploiting this vulnerability could lead to a system crash.

Introduced through
[email protected], [email protected] and others
Fixed in: [email protected], @4.2.10, @5.0.2

Detailed paths and remediation
Introduced through: [email protected][email protected]
Fix: Upgrade django to version 3.2.24 or 4.2.10 or 5.0.2
Introduced through: [email protected][email protected][email protected]
Fix: Pin django to version 3.2.24 or 4.2.10 or 5.0.2
Introduced through: [email protected][email protected][email protected]
Fix: Pin django to version 3.2.24 or 4.2.10 or 5.0.2
Introduced through: [email protected][email protected][email protected][email protected][email protected]
Fix: Pin django to version 3.2.24 or 4.2.10 or 5.0.2

Detailed paths and remediation
Introduced through: [email protected][email protected]
Fix: Upgrade django to version 3.2.24 or 4.2.10 or 5.0.2
Introduced through: [email protected][email protected][email protected]
Fix: Pin django to version 3.2.24 or 4.2.10 or 5.0.2
Introduced through: [email protected][email protected][email protected]
Fix: Pin django to version 3.2.24 or 4.2.10 or 5.0.2
Introduced through: [email protected][email protected][email protected][email protected][email protected]
Fix: Pin django to version 3.2.24 or 4.2.10 or 5.0.2

Completion criteria:

  • Upgrade django to version 3.2.24
@fec-jli fec-jli added Needs refinement Security: high Remediate within 30 days labels Feb 14, 2024
@fec-jli fec-jli added this to the Sprint 24.3 milestone Feb 14, 2024
@patphongs patphongs moved this to Sprint backlog in Website project Feb 23, 2024
@cnlucas cnlucas moved this from Sprint backlog to Assigned in Website project Feb 27, 2024
@pkfec pkfec linked a pull request Feb 28, 2024 that will close this issue
@pkfec pkfec moved this from 📥 Assigned to 🏗 In Progress in Website project Feb 28, 2024
@pkfec pkfec moved this from 🏗 In Progress to 👀 Ready in Website project Feb 28, 2024
@github-project-automation github-project-automation bot moved this from 👀 Ready to ✅ Done in Website project Mar 11, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Pipeline: Ready Security: high Remediate within 30 days
Projects
Status: ✅ Done
Development

Successfully merging a pull request may close this issue.

4 participants