Описание
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
A flaw was found in python-django. The parsed values of the Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial of service vector via excessive memory usage if large header values are sent.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 2 | python-django | Affected | ||
Red Hat Ceph Storage 3 | python-django | Out of support scope | ||
Red Hat OpenStack Platform 13 (Queens) | python-django | Out of support scope | ||
Red Hat OpenStack Platform 16.1 | python-django20 | Will not fix | ||
Red Hat OpenStack Platform 16.2 | python-django20 | Will not fix | ||
Red Hat OpenStack Platform 17.0 | python-django | Will not fix | ||
Red Hat Satellite 6 | satellite-capsule:el8/python-django | Affected | ||
Red Hat Satellite 6 | satellite:el8/python-django | Affected | ||
Red Hat Storage 3 | python-django | Affected | ||
Red Hat Update Infrastructure 3 for Cloud Providers | python-django | Will not fix |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, t ...
Django contains Uncontrolled Resource Consumption via cached header
Уязвимость программной платформы для веб-приложений Django, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3