CVE-2024-41989: Denial-Of-Service vulnerability in the floatformat template filter when input string contains a big exponent in scientific notation
Medium
Vulnerability Details
This vulnerability exists in the `floatformat` input filter when an attacker can pass a string with an `"e"` character in it to the input filter. This vulnerability takes advantage of the way strings with scientific exponents are converted internally to integers.
## Impact
An attacker can cause uncontrolled memory and resource consumption on a vulnerable django server.
(I have attached a screenrecording of the email conversation, the original email as an EML file, the original attachment as a zip file, a screenrecording of the entire email convo, the entire convo as a pdf file and a screenshot from the email convo. My personal email address is `███████` feel free to contact me directly if you have any questions.)
Actions
View on HackerOneReport Stats
- Report ID: 2644244
- State: Closed
- Substate: resolved
- Upvotes: 48