Bug 2337996 (CVE-2024-56374) - CVE-2024-56374 django: potential denial-of-service vulnerability in IPv6 validation [NEEDINFO]
Summary: CVE-2024-56374 django: potential denial-of-service vulnerability in IPv6 vali...
Keywords:
Status: NEW
Alias: CVE-2024-56374
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2338041 2338042 2338043
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-01-14 20:01 UTC by OSIDB Bzimport
Modified: 2025-05-29 20:01 UTC (History)
56 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:
selvakumar_eswaran: needinfo? (bzimport)
selvakumar_eswaran: needinfo? (rgatica)
selvakumar_eswaran: needinfo? (bzimport)
selvakumar_eswaran: needinfo? (rgatica)


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2025:0897 0 None None None 2025-02-03 15:14:22 UTC
Red Hat Product Errata RHSA-2025:0722 0 None None None 2025-01-27 22:41:16 UTC
Red Hat Product Errata RHSA-2025:0777 0 None None None 2025-01-28 19:17:15 UTC
Red Hat Product Errata RHSA-2025:0782 0 None None None 2025-01-28 22:39:49 UTC
Red Hat Product Errata RHSA-2025:2399 0 None None None 2025-03-05 14:27:36 UTC

Description OSIDB Bzimport 2025-01-14 20:01:34 UTC
An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

Comment 3 errata-xmlrpc 2025-01-27 22:41:13 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.4 for RHEL 8
  Red Hat Ansible Automation Platform 2.4 for RHEL 9

Via RHSA-2025:0722 https://access.redhat.com/errata/RHSA-2025:0722

Comment 4 errata-xmlrpc 2025-01-28 19:17:13 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2025:0777 https://access.redhat.com/errata/RHSA-2025:0777

Comment 5 errata-xmlrpc 2025-01-28 22:39:46 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 8
  Red Hat Ansible Automation Platform 2.5 for RHEL 9

Via RHSA-2025:0782 https://access.redhat.com/errata/RHSA-2025:0782

Comment 6 errata-xmlrpc 2025-03-05 14:27:33 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2025:2399 https://access.redhat.com/errata/RHSA-2025:2399

Comment 7 Selva 2025-03-18 09:11:45 UTC
Hi 

Redhat Ansible Automation Hub affected by CVE-2024-56374 ??  

As security scanner flagged the following.

Path              : /usr/lib/python3.9/site-packages/Django-4.2.16-py3.9.egg-info/Django
  Installed version : 4.2.16
  Fixed version     : 4.2.18

RHEL OS: RHEL 8.10
Ansible Automation Platform version : 2.4 
Ansible Automation Hub : 4.9.2

Comment 8 Selva 2025-03-18 09:14:22 UTC
Hi 

Redhat Ansible Automation Hub affected by CVE-2024-56374 ??  

As security scanner flagged the following.

Path              : /usr/lib/python3.9/site-packages/Django-4.2.16-py3.9.egg-info/Django
  Installed version : 4.2.16
  Fixed version     : 4.2.18

RHEL OS: RHEL 8.10
Ansible Automation Platform version : 2.4 
Ansible Automation Hub : 4.9.2

Comment 9 Selva 2025-03-18 09:14:53 UTC
Hi 

Redhat Ansible Automation Hub affected by CVE-2024-56374 ??  

As security scanner flagged the following.

Path              : /usr/lib/python3.9/site-packages/Django-4.2.16-py3.9.egg-info/Django
  Installed version : 4.2.16
  Fixed version     : 4.2.18

RHEL OS: RHEL 8.10
Ansible Automation Platform version : 2.4 
Ansible Automation Hub : 4.9.2

Comment 10 Ricardo Santamaria 2025-04-22 18:49:30 UTC
Per comment #6 and 

 Red Hat Satellite 6.16 for RHEL 8 Via RHSA-2025:2399 https://access.redhat.com/errata/RHSA-2025:2399

Can this be backported for Satellite 6.15 for RHEL 8? What may be the timeline for that to occur?


Note You need to log in before you can comment on or make changes to this bug.