Описание
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
An uncontrolled resource consumption vulnerability was found in Django. Feeding certain inputs with a very large number of Unicode characters to the URI to IRI encoder function can lead to a denial of service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Certification for Red Hat Enterprise Linux 7 | python-django | Affected | ||
Red Hat OpenStack Platform 16.1 | python-django20 | Out of support scope | ||
Red Hat OpenStack Platform 16.2 | python-django20 | Out of support scope | ||
Red Hat OpenStack Platform 17.0 | python-django | Out of support scope | ||
Red Hat OpenStack Platform 17.1 | python-django | Out of support scope | ||
Red Hat OpenStack Platform 18.0 | python-django | Affected | ||
Red Hat Storage 3 | python-django | Affected | ||
Red Hat Ansible Automation Platform 2.3 for RHEL 8 | automation-controller | Fixed | RHSA-2023:5701 | 16.10.2023 |
Red Hat Ansible Automation Platform 2.3 for RHEL 9 | automation-controller | Fixed | RHSA-2023:5701 | 16.10.2023 |
Red Hat Ansible Automation Platform 2.4 for RHEL 8 | python3x-django | Fixed | RHSA-2023:5208 | 18.09.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, ...
Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
Уязвимость компонента django.utils.encoding.uri_to_iri() программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3