VDB
Sign up
—

PYSEC-2021-64

Quick fix

PYSEC-2021-64 — django-filter: upgrade to the fixed version with the command below.

pip install --upgrade 'django-filter>=340cf7a23a2b3dcd7183f6a0d6c383e85b130d2b'

Details

django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input using exponential format with sufficiently large exponents. Version 2.4.0+ applies a `MaxValueValidator` with a a default `limit_value` of 1e50 to the form field used by `NumberFilter` instances. In addition, `NumberFilter` implements the new `get_max_validator()` which should return a configured validator instance to customise the limit, or else `None` to disable the additional validation. Users may manually apply an equivalent validator if they are not able to upgrade.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django-filter
Introduced in: 0Fixed in: 340cf7a23a2b3dcd7183f6a0d6c383e85b130d2b
Fixpip install --upgrade 'django-filter>=340cf7a23a2b3dcd7183f6a0d6c383e85b130d2b'

References