Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
| Software | From | Fixed in |
|---|---|---|
| djangoproject / django | 1.11.0 | 1.11.19 |
| djangoproject / django | 2.0.0 | 2.0.11 |
| djangoproject / django | 2.1.0 | 2.1.6 |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 18.04 | 18.04.x |
| canonical / ubuntu_linux | 18.10 | 18.10.x |
| fedoraproject / fedora | 28 | 28.x |
| fedoraproject / fedora | 29 | 29.x |
Django
|
- | 1.11.19 |
Django
|
2.0.0 | 2.0.11 |
Django
|
2.1.0 | 2.1.6 |