{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2018-7536","title":"Title"},{"category":"description","text":"An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2018-7536","url":"https://www.suse.com/security/cve/CVE-2018-7536"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1083304 for CVE-2018-7536","url":"https://bugzilla.suse.com/1083304"},{"category":"external","summary":"Advisory link for SUSE-SU-2018:0973-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2018-April/003895.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2018:1102-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2018-April/003965.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2018:1828-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2018-June/004225.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2018:1830-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2018-June/004226.html"},{"category":"external","summary":"Advisory link for openSUSE-SU-2023:0077-1","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OGS4NP24275NERRPQV6A6EONV6W3C2SK/"}],"title":"SUSE CVE CVE-2018-7536","tracking":{"current_release_date":"2026-01-04T00:38:00Z","generator":{"date":"2023-02-15T04:29:38Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2018-7536","initial_release_date":"2023-02-15T04:29:38Z","revision_history":[{"date":"2023-02-15T04:29:38Z","number":"2","summary":"Current version"},{"date":"2023-03-21T03:41:04Z","number":"3","summary":"Current version"},{"date":"2023-12-08T04:13:14Z","number":"4","summary":"Current version"},{"date":"2024-07-20T04:14:48Z","number":"5","summary":"Current version"},{"date":"2025-01-01T07:49:40Z","number":"6","summary":"Current version"},{"date":"2025-02-08T06:06:53Z","number":"7","summary":"Current version"},{"date":"2025-03-15T12:28:28Z","number":"8","summary":"Current version"},{"date":"2025-04-25T07:10:05Z","number":"9","summary":"Current version"},{"date":"2025-10-07T09:59:02Z","number":"10","summary":"Current version"},{"date":"2026-01-04T00:38:00Z","number":"11","summary":"more updates released"}],"status":"interim","version":"11"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SUSE Enterprise Storage 4","product":{"name":"SUSE Enterprise Storage 4","product_id":"SUSE Enterprise Storage 4","product_identification_helper":{"cpe":"cpe:/o:suse:ses:4"}}},{"category":"product_name","name":"SUSE Enterprise Storage 5","product":{"name":"SUSE Enterprise Storage 5","product_id":"SUSE Enterprise Storage 5","product_identification_helper":{"cpe":"cpe:/o:suse:ses:5"}}},{"category":"product_name","name":"SUSE OpenStack Cloud 6","product":{"name":"SUSE OpenStack Cloud 6","product_id":"SUSE OpenStack Cloud 6","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud:6"}}},{"category":"product_name","name":"SUSE OpenStack Cloud 7","product":{"name":"SUSE OpenStack Cloud 7","product_id":"SUSE OpenStack Cloud 7","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud:7"}}},{"category":"product_name","name":"SUSE Package Hub 12","product":{"name":"SUSE Package Hub 12","product_id":"SUSE Package Hub 12","product_identification_helper":{"cpe":"cpe:/o:suse:packagehub:12"}}},{"category":"product_name","name":"SUSE Package Hub 12 SP1","product":{"name":"SUSE Package Hub 12 SP1","product_id":"SUSE Package Hub 12 SP1","product_identification_helper":{"cpe":"cpe:/o:suse:packagehub:12:sp1"}}},{"category":"product_name","name":"openSUSE Tumbleweed","product":{"name":"openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed","product_identification_helper":{"cpe":"cpe:/o:opensuse:tumbleweed"}}},{"category":"product_version","name":"python-Django-1.11.11-8.1","product":{"name":"python-Django-1.11.11-8.1","product_id":"python-Django-1.11.11-8.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:1.11.11:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python-Django@1.11.11-8.1?upstream=python-Django-1.11.11-8.1.src.rpm"}}},{"category":"product_version","name":"python-Django-1.11.15-2.1","product":{"name":"python-Django-1.11.15-2.1","product_id":"python-Django-1.11.15-2.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:1.11.15:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python-Django@1.11.15-2.1?upstream=python-Django-1.11.15-2.1.src.rpm"}}},{"category":"product_version","name":"python-Django-1.6.11-5.5.1","product":{"name":"python-Django-1.6.11-5.5.1","product_id":"python-Django-1.6.11-5.5.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:1.6.11:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python-Django@1.6.11-5.5.1?upstream=python-Django-1.6.11-5.5.1.src.rpm"}}},{"category":"product_version","name":"python-Django-1.6.11-6.5.1","product":{"name":"python-Django-1.6.11-6.5.1","product_id":"python-Django-1.6.11-6.5.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:1.6.11:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python-Django@1.6.11-6.5.1?upstream=python-Django-1.6.11-6.5.1.src.rpm"}}},{"category":"product_version","name":"python-Django-1.8.19-3.4.1","product":{"name":"python-Django-1.8.19-3.4.1","product_id":"python-Django-1.8.19-3.4.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:1.8.19:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python-Django@1.8.19-3.4.1?upstream=python-Django-1.8.19-3.4.1.src.rpm"}}},{"category":"product_version","name":"python-Django-1.8.19-3.6.1","product":{"name":"python-Django-1.8.19-3.6.1","product_id":"python-Django-1.8.19-3.6.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:1.8.19:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python-Django@1.8.19-3.6.1?upstream=python-Django-1.8.19-3.6.1.src.rpm"}}},{"category":"product_version","name":"python310-Django-4.2.11-2.1","product":{"name":"python310-Django-4.2.11-2.1","product_id":"python310-Django-4.2.11-2.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:4.2.11:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python310-Django@4.2.11-2.1"}}},{"category":"product_version","name":"python310-Django4-4.2.14-1.1","product":{"name":"python310-Django4-4.2.14-1.1","product_id":"python310-Django4-4.2.14-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python310-Django4@4.2.14-1.1"}}},{"category":"product_version","name":"python311-Django-4.2.11-2.1","product":{"name":"python311-Django-4.2.11-2.1","product_id":"python311-Django-4.2.11-2.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:4.2.11:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python311-Django@4.2.11-2.1?upstream=python-Django-4.2.11-2.1.src.rpm"}}},{"category":"product_version","name":"python311-Django4-4.2.14-1.1","product":{"name":"python311-Django4-4.2.14-1.1","product_id":"python311-Django4-4.2.14-1.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:4.2.14:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python311-Django4@4.2.14-1.1"}}},{"category":"product_version","name":"python312-Django-4.2.11-2.1","product":{"name":"python312-Django-4.2.11-2.1","product_id":"python312-Django-4.2.11-2.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:4.2.11:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python312-Django@4.2.11-2.1"}}},{"category":"product_version","name":"python312-Django4-4.2.14-1.1","product":{"name":"python312-Django4-4.2.14-1.1","product_id":"python312-Django4-4.2.14-1.1","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:4.2.14:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python312-Django4@4.2.14-1.1"}}},{"category":"product_version","name":"python312-Django6-6.0-1.1","product":{"name":"python312-Django6-6.0-1.1","product_id":"python312-Django6-6.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python312-Django6@6.0-1.1"}}},{"category":"product_version","name":"python313-Django6-6.0-1.1","product":{"name":"python313-Django6-6.0-1.1","product_id":"python313-Django6-6.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python313-Django6@6.0-1.1"}}},{"category":"product_version","name":"python36-Django-3.2.7-2.3","product":{"name":"python36-Django-3.2.7-2.3","product_id":"python36-Django-3.2.7-2.3","product_identification_helper":{"purl":"pkg:rpm/suse/python36-Django@3.2.7-2.3"}}},{"category":"product_version","name":"python38-Django-3.2.7-2.3","product":{"name":"python38-Django-3.2.7-2.3","product_id":"python38-Django-3.2.7-2.3","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:3.2.7:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python38-Django@3.2.7-2.3"}}},{"category":"product_version","name":"python39-Django-3.2.7-2.3","product":{"name":"python39-Django-3.2.7-2.3","product_id":"python39-Django-3.2.7-2.3","product_identification_helper":{"cpe":"cpe:2.3:a:djangoproject:django:3.2.7:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/python39-Django@3.2.7-2.3"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"python-Django-1.6.11-5.5.1 as component of SUSE Enterprise Storage 4","product_id":"SUSE Enterprise Storage 4:python-Django-1.6.11-5.5.1"},"product_reference":"python-Django-1.6.11-5.5.1","relates_to_product_reference":"SUSE Enterprise Storage 4"},{"category":"default_component_of","full_product_name":{"name":"python-Django-1.6.11-6.5.1 as component of SUSE Enterprise Storage 5","product_id":"SUSE Enterprise Storage 5:python-Django-1.6.11-6.5.1"},"product_reference":"python-Django-1.6.11-6.5.1","relates_to_product_reference":"SUSE Enterprise Storage 5"},{"category":"default_component_of","full_product_name":{"name":"python-Django-1.8.19-3.6.1 as component of SUSE OpenStack Cloud 6","product_id":"SUSE OpenStack Cloud 6:python-Django-1.8.19-3.6.1"},"product_reference":"python-Django-1.8.19-3.6.1","relates_to_product_reference":"SUSE OpenStack Cloud 6"},{"category":"default_component_of","full_product_name":{"name":"python-Django-1.8.19-3.4.1 as component of SUSE OpenStack Cloud 7","product_id":"SUSE OpenStack Cloud 7:python-Django-1.8.19-3.4.1"},"product_reference":"python-Django-1.8.19-3.4.1","relates_to_product_reference":"SUSE OpenStack Cloud 7"},{"category":"default_component_of","full_product_name":{"name":"python-Django-1.11.11-8.1 as component of SUSE Package Hub 12","product_id":"SUSE Package Hub 12:python-Django-1.11.11-8.1"},"product_reference":"python-Django-1.11.11-8.1","relates_to_product_reference":"SUSE Package Hub 12"},{"category":"default_component_of","full_product_name":{"name":"python-Django-1.11.15-2.1 as component of SUSE Package Hub 12 SP1","product_id":"SUSE Package Hub 12 SP1:python-Django-1.11.15-2.1"},"product_reference":"python-Django-1.11.15-2.1","relates_to_product_reference":"SUSE Package Hub 12 SP1"},{"category":"default_component_of","full_product_name":{"name":"python310-Django-4.2.11-2.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python310-Django-4.2.11-2.1"},"product_reference":"python310-Django-4.2.11-2.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python310-Django4-4.2.14-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python310-Django4-4.2.14-1.1"},"product_reference":"python310-Django4-4.2.14-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python311-Django-4.2.11-2.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python311-Django-4.2.11-2.1"},"product_reference":"python311-Django-4.2.11-2.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python311-Django4-4.2.14-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python311-Django4-4.2.14-1.1"},"product_reference":"python311-Django4-4.2.14-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python312-Django-4.2.11-2.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python312-Django-4.2.11-2.1"},"product_reference":"python312-Django-4.2.11-2.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python312-Django4-4.2.14-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python312-Django4-4.2.14-1.1"},"product_reference":"python312-Django4-4.2.14-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python312-Django6-6.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python312-Django6-6.0-1.1"},"product_reference":"python312-Django6-6.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python313-Django6-6.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python313-Django6-6.0-1.1"},"product_reference":"python313-Django6-6.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python36-Django-3.2.7-2.3 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python36-Django-3.2.7-2.3"},"product_reference":"python36-Django-3.2.7-2.3","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python38-Django-3.2.7-2.3 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python38-Django-3.2.7-2.3"},"product_reference":"python38-Django-3.2.7-2.3","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python39-Django-3.2.7-2.3 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python39-Django-3.2.7-2.3"},"product_reference":"python39-Django-3.2.7-2.3","relates_to_product_reference":"openSUSE Tumbleweed"}]},"vulnerabilities":[{"cve":"CVE-2018-7536","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2018-7536"}],"notes":[{"category":"general","text":"An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.","title":"CVE description"}],"product_status":{"recommended":["SUSE Enterprise Storage 4:python-Django-1.6.11-5.5.1","SUSE Enterprise Storage 5:python-Django-1.6.11-6.5.1","SUSE OpenStack Cloud 6:python-Django-1.8.19-3.6.1","SUSE OpenStack Cloud 7:python-Django-1.8.19-3.4.1","SUSE Package Hub 12 SP1:python-Django-1.11.15-2.1","SUSE Package Hub 12:python-Django-1.11.11-8.1","openSUSE Tumbleweed:python310-Django-4.2.11-2.1","openSUSE Tumbleweed:python310-Django4-4.2.14-1.1","openSUSE Tumbleweed:python311-Django-4.2.11-2.1","openSUSE Tumbleweed:python311-Django4-4.2.14-1.1","openSUSE Tumbleweed:python312-Django-4.2.11-2.1","openSUSE Tumbleweed:python312-Django4-4.2.14-1.1","openSUSE Tumbleweed:python312-Django6-6.0-1.1","openSUSE Tumbleweed:python313-Django6-6.0-1.1","openSUSE Tumbleweed:python36-Django-3.2.7-2.3","openSUSE Tumbleweed:python38-Django-3.2.7-2.3","openSUSE Tumbleweed:python39-Django-3.2.7-2.3"]},"references":[{"category":"external","summary":"CVE-2018-7536","url":"https://www.suse.com/security/cve/CVE-2018-7536"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1083304 for CVE-2018-7536","url":"https://bugzilla.suse.com/1083304"},{"category":"external","summary":"Advisory link for SUSE-SU-2018:0973-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2018-April/003895.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2018:1102-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2018-April/003965.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2018:1828-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2018-June/004225.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2018:1830-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2018-June/004226.html"},{"category":"external","summary":"Advisory link for openSUSE-SU-2023:0077-1","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OGS4NP24275NERRPQV6A6EONV6W3C2SK/"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["SUSE Enterprise Storage 4:python-Django-1.6.11-5.5.1","SUSE Enterprise Storage 5:python-Django-1.6.11-6.5.1","SUSE OpenStack Cloud 6:python-Django-1.8.19-3.6.1","SUSE OpenStack Cloud 7:python-Django-1.8.19-3.4.1","SUSE Package Hub 12 SP1:python-Django-1.11.15-2.1","SUSE Package Hub 12:python-Django-1.11.11-8.1","openSUSE Tumbleweed:python310-Django-4.2.11-2.1","openSUSE Tumbleweed:python310-Django4-4.2.14-1.1","openSUSE Tumbleweed:python311-Django-4.2.11-2.1","openSUSE Tumbleweed:python311-Django4-4.2.14-1.1","openSUSE Tumbleweed:python312-Django-4.2.11-2.1","openSUSE Tumbleweed:python312-Django4-4.2.14-1.1","openSUSE Tumbleweed:python312-Django6-6.0-1.1","openSUSE Tumbleweed:python313-Django6-6.0-1.1","openSUSE Tumbleweed:python36-Django-3.2.7-2.3","openSUSE Tumbleweed:python38-Django-3.2.7-2.3","openSUSE Tumbleweed:python39-Django-3.2.7-2.3"]}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.0"},"products":["SUSE Enterprise Storage 4:python-Django-1.6.11-5.5.1","SUSE Enterprise Storage 5:python-Django-1.6.11-6.5.1","SUSE OpenStack Cloud 6:python-Django-1.8.19-3.6.1","SUSE OpenStack Cloud 7:python-Django-1.8.19-3.4.1","SUSE Package Hub 12 SP1:python-Django-1.11.15-2.1","SUSE Package Hub 12:python-Django-1.11.11-8.1","openSUSE Tumbleweed:python310-Django-4.2.11-2.1","openSUSE Tumbleweed:python310-Django4-4.2.14-1.1","openSUSE Tumbleweed:python311-Django-4.2.11-2.1","openSUSE Tumbleweed:python311-Django4-4.2.14-1.1","openSUSE Tumbleweed:python312-Django-4.2.11-2.1","openSUSE Tumbleweed:python312-Django4-4.2.14-1.1","openSUSE Tumbleweed:python312-Django6-6.0-1.1","openSUSE Tumbleweed:python313-Django6-6.0-1.1","openSUSE Tumbleweed:python36-Django-3.2.7-2.3","openSUSE Tumbleweed:python38-Django-3.2.7-2.3","openSUSE Tumbleweed:python39-Django-3.2.7-2.3"]}],"threats":[{"category":"impact","date":"2018-02-28T14:53:41Z","details":"moderate"}],"title":"CVE-2018-7536"}]}