Vulnerability Details CVE-2020-15225
django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input using exponential format with sufficiently large exponents. Version 2.4.0+ applies a `MaxValueValidator` with a a default `limit_value` of 1e50 to the form field used by `NumberFilter` instances. In addition, `NumberFilter` implements the new `get_max_validator()` which should return a configured validator instance to customise the limit, or else `None` to disable the additional validation. Users may manually apply an equivalent validator if they are not able to upgrade.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 4.0
Products affected by CVE-2020-15225
-
cpe:2.3:a:django-filter_project:django-filter:0.1.0
-
cpe:2.3:a:django-filter_project:django-filter:0.10.0
-
cpe:2.3:a:django-filter_project:django-filter:0.11.0
-
cpe:2.3:a:django-filter_project:django-filter:0.12.0
-
cpe:2.3:a:django-filter_project:django-filter:0.13
-
cpe:2.3:a:django-filter_project:django-filter:0.14.0
-
cpe:2.3:a:django-filter_project:django-filter:0.15.0
-
cpe:2.3:a:django-filter_project:django-filter:0.15.1
-
cpe:2.3:a:django-filter_project:django-filter:0.15.2
-
cpe:2.3:a:django-filter_project:django-filter:0.15.3
-
cpe:2.3:a:django-filter_project:django-filter:0.2.0
-
cpe:2.3:a:django-filter_project:django-filter:0.5.0
-
cpe:2.3:a:django-filter_project:django-filter:0.5.1
-
cpe:2.3:a:django-filter_project:django-filter:0.5.2
-
cpe:2.3:a:django-filter_project:django-filter:0.5.3
-
cpe:2.3:a:django-filter_project:django-filter:0.5.4
-
cpe:2.3:a:django-filter_project:django-filter:0.6
-
cpe:2.3:a:django-filter_project:django-filter:0.7
-
cpe:2.3:a:django-filter_project:django-filter:0.8
-
cpe:2.3:a:django-filter_project:django-filter:0.9.0
-
cpe:2.3:a:django-filter_project:django-filter:0.9.1
-
cpe:2.3:a:django-filter_project:django-filter:0.9.2
-
cpe:2.3:a:django-filter_project:django-filter:1.0.0
-
cpe:2.3:a:django-filter_project:django-filter:1.0.1
-
cpe:2.3:a:django-filter_project:django-filter:1.0.2
-
cpe:2.3:a:django-filter_project:django-filter:1.0.3
-
cpe:2.3:a:django-filter_project:django-filter:1.0.4
-
cpe:2.3:a:django-filter_project:django-filter:1.1.0
-
cpe:2.3:a:django-filter_project:django-filter:2.0.0
-
cpe:2.3:a:django-filter_project:django-filter:2.1.0
-
cpe:2.3:a:django-filter_project:django-filter:2.2.0
-
cpe:2.3:a:django-filter_project:django-filter:2.3.0
-
cpe:2.3:o:fedoraproject:fedora:34
-
cpe:2.3:o:fedoraproject:fedora:35