The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-django | Jul 30, 2024 | Aug 26, 2014 |
| Freebsd | — | Upgrade py34-djangoUpgrade py32-djangoUpgrade py27-django14Upgrade py32-django-develUpgrade py33-django-develUpgrade py32-django15Upgrade py27-django15Upgrade py27-django-develUpgrade py34-django-develUpgrade py34-django15Upgrade py33-django15Upgrade py27-djangoUpgrade py33-django | Dec 10, 2025 | Aug 21, 2014 |
| Gentoo Linux | — | Upgrade dev-python/django. | Oct 30, 2017 | Aug 26, 2014 |
| Suse | — | Upgrade python-django | Dec 18, 2015 | Aug 26, 2014 |
| Ubuntu | — | Upgrade python-django | Nov 8, 2024 | Aug 26, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub