Описание
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
A denial of service flaw was discovered in Django. This issue occurs when incorrectly handling certain internationalized URLs. A malicious attacker could use this issue to cause a crash, resulting in a denial of service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 2 | python-django | Affected | ||
Red Hat Ceph Storage 3 | python-django | Not affected | ||
Red Hat OpenStack Platform 13 (Queens) | python-django | Not affected | ||
Red Hat OpenStack Platform 16.1 | python-django20 | Not affected | ||
Red Hat OpenStack Platform 16.2 | python-django20 | Not affected | ||
Red Hat Satellite 6 | satellite-capsule:el8/python-django | Affected | ||
Red Hat Satellite 6 | satellite:el8/python-django | Affected | ||
Red Hat Storage 3 | python-django | Not affected | ||
Red Hat Update Infrastructure 3 for Cloud Providers | python-django | Not affected | ||
Red Hat Satellite 6.13 for RHEL 8 | python-django | Fixed | RHSA-2023:2097 | 03.05.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, i ...
Django denial-of-service vulnerability in internationalized URLs
Уязвимость программной платформы для веб-приложений Django, связанная с недостаточной обработкой регулярных выражений, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3