Django Wiki Vulnerability: Malicious Article Content Can Cause Severe CPU Usage
CVE-2024-28865

7.5HIGH

Key Information:

Vendor
CVE Published:
18 March 2024

What is CVE-2024-28865?

A vulnerability in django-wiki, a wiki system designed for Django, allows attackers to exploit maliciously crafted article content, leading to significant server CPU usage due to a regular expression loop. This issue affects all installations of django-wiki prior to version 0.10.1. Administrators are advised to upgrade to this version or implement access restrictions to prevent anonymous users from creating or editing articles as a temporary measure.

Affected Version(s)

django-wiki < 0.10.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.