Show plain JSON{"id": "CVE-2015-0222", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2015-01-16T16:59:21.217", "references": [{"url": "http://advisories.mageia.org/MGASA-2015-0026.html", "source": "secalert@redhat.com"}, {"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148485.html", "source": "secalert@redhat.com"}, {"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148608.html", "source": "secalert@redhat.com"}, {"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148696.html", "source": "secalert@redhat.com"}, {"url": "http://lists.opensuse.org/opensuse-updates/2015-04/msg00001.html", "source": "secalert@redhat.com"}, {"url": "http://lists.opensuse.org/opensuse-updates/2015-09/msg00035.html", "source": "secalert@redhat.com"}, {"url": "http://secunia.com/advisories/62285", "source": "secalert@redhat.com"}, {"url": "http://secunia.com/advisories/62309", "source": "secalert@redhat.com"}, {"url": "http://ubuntu.com/usn/usn-2469-1", "tags": ["Patch", "Vendor Advisory"], "source": "secalert@redhat.com"}, {"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:109", "source": "secalert@redhat.com"}, {"url": "https://www.djangoproject.com/weblog/2015/jan/13/security/", "tags": ["Patch", "Vendor Advisory"], "source": "secalert@redhat.com"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-17"}]}], "descriptions": [{"lang": "en", "value": "ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries."}, {"lang": "es", "value": "ModelMultipleChoiceField en Django 1.6.x anterior a 1.6.10 y 1.7.x anterior a 1.7.3, cuando show_hidden_initial est\u00e1 configurado a 'True', permite a atacantes remotos causar una denegaci\u00f3n de servicio mediante la presentaci\u00f3n de valores duplicados, lo que provoca un n\u00famero grande de consultas SQL."}], "lastModified": "2016-12-22T02:59:23.080", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.04:*:lts:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "823E02CA-A145-46C2-BC4C-16DECB060B19"}, {"criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:lts:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E685F933-7C10-49B6-9F4B-89478AF51761"}, {"criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*", "vulnerable": true, "matchCriteriaId": "B5A6F2F3-4894-4392-8296-3B8DD2679084"}, {"criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49A63F39-30BE-443F-AF10-6245587D3359"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E636F6CA-1979-43DA-A12F-23EC009B4A65", "versionEndIncluding": "1.4.17"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5463AB51-6088-473A-BB54-BB78ACFC6DCA"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0CC369A0-0092-450D-91E9-13C7AF7EBC16"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B6B7974-ABEF-4E0C-8503-6E9C22D28C78"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55460F1D-661B-465C-8A22-E4E6DA2834B3"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9FD4FB46-3A98-4B9B-A241-C39E2C2A0FEC"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF87FDAB-51A2-41C4-A4C4-5180B0230C3F"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80E8431B-FEA1-4D94-B367-56E8678C3CD3"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81E7779A-EDB9-4871-8D7C-63C5A7C7A0DB"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABB56113-5E66-4EE9-B551-FD40C2FE307B"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.6.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2985241-279F-46AC-8BBF-DF2F439FE720"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72653EB4-CE19-42FC-9C99-5CB391DABE7E"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06513AE1-11E4-4A9C-BDA4-D0511A9DCFC8"}, {"criteria": "cpe:2.3:a:djangoproject:django:1.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6004EA17-A2B4-4E4C-A738-210FCAC2CA32"}], "operator": "OR"}]}], "sourceIdentifier": "secalert@redhat.com"}