Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hrw-hx67-34x6

Опубликовано: 15 фев. 2023
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Resource exhaustion in Django

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

Ссылки

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 3.2a1, < 3.2.18

3.2.18

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.1a1, < 4.1.7

4.1.7

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.0a1, < 4.0.10

4.0.10

EPSS

Процентиль: 94%
0.16091
Средний

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
redhat
больше 2 лет назад

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
nvd
больше 2 лет назад

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
debian
больше 2 лет назад

An issue was discovered in the Multipart Request Parser in Django 3.2 ...

suse-cvrf
больше 2 лет назад

Security update for python-Django

EPSS

Процентиль: 94%
0.16091
Средний

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400