python-django: Potential denial-of-service vulnerability in internationalized URLs
Published Oct 16, 2022
8.7
HIGHCVSS 4.0
EPSS 3.01%
Description
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
Affected products
No data.
- ≥ 3.2 · < 3.2.16
- ≥ 4.0 · < 4.0.8
- ≥ 4.1 · < 4.1.2
No data.
RHUI 4 for RHEL 8
python-django-0:3.2.16-1.0.1.el8ui
Fixed · RHSA-2023:0742
Red Hat Satellite 6.13 for RHEL 8
python-django-0:3.2.18-1.el8pc
Fixed · RHSA-2023:2097
Red Hat Satellite 6.13 for RHEL 8
python-django-0:3.2.18-1.el8pc
Fixed · RHSA-2023:2097
Red Hat Ansible Automation Platform 2
python-django
Affected
Red Hat Ceph Storage 3
python-django
Not affected
Red Hat OpenStack Platform 13 (Queens)
python-django
Not affected
Red Hat OpenStack Platform 16.1
python-django20
Not affected
Red Hat OpenStack Platform 16.2
python-django20
Not affected
Red Hat Satellite 6
satellite-capsule:el8/python-django
Affected
Red Hat Satellite 6
satellite:el8/python-django
Affected
Red Hat Storage 3
python-django
Not affected
Red Hat Update Infrastructure 3 for Cloud Providers
python-django
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHUI 4 for RHEL 8 | python-django-0:3.2.16-1.0.1.el8ui | Fixed | RHSA-2023:0742 |
| Red Hat Satellite 6.13 for RHEL 8 | python-django-0:3.2.18-1.el8pc | Fixed | RHSA-2023:2097 |
| Red Hat Satellite 6.13 for RHEL 8 | python-django-0:3.2.18-1.el8pc | Fixed | RHSA-2023:2097 |
| Red Hat Ansible Automation Platform 2 | python-django | Affected | n/a |
| Red Hat Ceph Storage 3 | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 16.1 | python-django20 | Not affected | n/a |
| Red Hat OpenStack Platform 16.2 | python-django20 | Not affected | n/a |
| Red Hat Satellite 6 | satellite-capsule:el8/python-django | Affected | n/a |
| Red Hat Satellite 6 | satellite:el8/python-django | Affected | n/a |
| Red Hat Storage 3 | python-django | Not affected | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | python-django | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (25)
- https://access.redhat.com/security/cve/CVE-2022-41323 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2136130 Issue Tracking
- https://docs.djangoproject.com/en/4.0/releases/security Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0094 Advisory
- https://github.com/advisories/GHSA-qrw5-5h28-6cmg Advisory
- https://github.com/django/django/commit/23f0093125ac2e553da6c1b2f9988eb6a3dd2ea1
- https://github.com/django/django/commit/5b6b257fa7ec37ff27965358800c67e2dd11c924 PatchThird Party Advisory
- https://github.com/django/django/commit/9d656ea51d9ea7105c0c0785783ac29d426a7d25
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2022-304.yaml
- https://groups.google.com/forum/#!forum/django-announce
- https://groups.google.com/forum/#%21forum/django-announce
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FKYVMMR7RPM6AHJ2SBVM2LO6D3NGFY7B/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VZS4G6NSZWPTVXMMZHJOJVQEPL3QTO77/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJB6FUBBLVKKG655UMTLQNN6UQ6EDLSP/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FKYVMMR7RPM6AHJ2SBVM2LO6D3NGFY7B
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZS4G6NSZWPTVXMMZHJOJVQEPL3QTO77
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJB6FUBBLVKKG655UMTLQNN6UQ6EDLSP
- https://nvd.nist.gov/vuln/detail/CVE-2022-41323
- https://security.netapp.com/advisory/ntap-20221124-0001 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-41323
- https://www.djangoproject.com/weblog/2022/oct/04/security-releases Vendor Advisory
Change history (0)
No recorded changes yet.