Skip to main content

Threats Tagged 'cve-2024-27351'

View all threats tagged with 'cve-2024-27351'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-27351

Threats Tagged 'cve-2024-27351'

Click on any threat for detailed analysis and mitigation recommendations

A potential regular expression denial-of-service (ReDoS) vulnerability exists in the django.utils.text. Truncator.words() function in the python-django package used by Red Hat OpenStack Platform 17.1. This vulnerability is identified as CVE-2024-27351 and has been rated with moderate severity by Red Hat Product Security. The issue could allow an attacker to cause a denial-of-service condition by exploiting inefficient regular expression processing. Red Hat has issued a security update addressing this vulnerability for affected versions. No known exploits are reported in the wild at this time.

Join the discussion

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Users of Red Hat Satellite are advised to upgrade to these updated packages, which fix these bugs.

Join the discussion
CVE-2024-27351: n/aCVE-2024-27351
0

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2024-27351
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses