Описание
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.
A bypass of validation flaw was found in python-django. When uploading multiple files using one form field, an attacker could upload multiple files without validation due to the server only validating the last file uploaded.
Отчет
Red Hat Satellite and Red Hat Update Infrastructure individual impact ratings have been set to Low since initial privileges are required in order to access the server and the vulnerable functionality.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 2 | python-django | Not affected | ||
Red Hat Ceph Storage 3 | python-django | Not affected | ||
Red Hat OpenStack Platform 13 (Queens) | python-django | Not affected | ||
Red Hat OpenStack Platform 16.1 | python-django20 | Not affected | ||
Red Hat OpenStack Platform 16.2 | python-django20 | Not affected | ||
Red Hat OpenStack Platform 17.0 | python-django | Not affected | ||
Red Hat Storage 3 | python-django | Not affected | ||
Red Hat Satellite 6.13 for RHEL 8 | python-django | Fixed | RHSA-2023:5931 | 19.10.2023 |
Red Hat Satellite 6.13 for RHEL 8 | python-django | Fixed | RHSA-2023:5931 | 19.10.2023 |
Red Hat Satellite 6.14 for RHEL 8 | python-django | Fixed | RHSA-2023:6818 | 08.11.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, i ...
Django bypasses validation when using one form field to upload multiple files
EPSS
6.5 Medium
CVSS3