Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2023:0062-1

Опубликовано: 28 фев. 2023
Источник: suse-cvrf

Описание

Security update for python-Django

python-Django was updated to fix a security issues:

  • CVE-2023-24580: prevent DOS in file uploads (bsc#1208082)

Список пакетов

SUSE Package Hub 15 SP4
python3-Django-2.2.28-bp154.2.9.1
openSUSE Leap 15.4
python3-Django-2.2.28-bp154.2.9.1

Описание

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.


Затронутые продукты
SUSE Package Hub 15 SP4:python3-Django-2.2.28-bp154.2.9.1
openSUSE Leap 15.4:python3-Django-2.2.28-bp154.2.9.1

Ссылки