CVE-2024-41989: Denial-Of-Service vulnerability in the floatformat template filter when input string contains a big exponent in scientific notation

Disclosed: 2024-09-22 20:59:30 By l33thaxor To ibb
Medium
Vulnerability Details
This vulnerability exists in the `floatformat` input filter when an attacker can pass a string with an `"e"` character in it to the input filter. This vulnerability takes advantage of the way strings with scientific exponents are converted internally to integers. ## Impact An attacker can cause uncontrolled memory and resource consumption on a vulnerable django server. (I have attached a screenrecording of the email conversation, the original email as an EML file, the original attachment as a zip file, a screenrecording of the entire email convo, the entire convo as a pdf file and a screenshot from the email convo. My personal email address is `███████` feel free to contact me directly if you have any questions.)
Actions
View on HackerOne
Report Stats
  • Report ID: 2644244
  • State: Closed
  • Substate: resolved
  • Upvotes: 48
Share this report