python-django: Potential denial-of-service via Accept-Language headers
Published Feb 1, 2023
8.7
HIGHCVSS 4.0
EPSS 47.38%
Description
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
Affected products
No data.
Configuration 1
- ≥ 3.2 · < 3.2.17
- ≥ 4.0 · < 4.0.9
- ≥ 4.1 · < 4.1.6
Configuration 2
- 10.0
No data.
RHUI 4 for RHEL 8
python-django-0:3.2.18-1.0.1.el8ui
Fixed · RHSA-2023:2101
Red Hat Satellite 6.13 for RHEL 8
python-django-0:3.2.18-1.el8pc
Fixed · RHSA-2023:2097
Red Hat Satellite 6.13 for RHEL 8
python-django-0:3.2.18-1.el8pc
Fixed · RHSA-2023:2097
Red Hat Ansible Automation Platform 2
python-django
Affected
Red Hat Ceph Storage 3
python-django
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
python-django
Out of support scope
Red Hat OpenStack Platform 16.1
python-django20
Will not fix
Red Hat OpenStack Platform 16.2
python-django20
Will not fix
Red Hat OpenStack Platform 17.0
python-django
Will not fix
Red Hat Satellite 6
satellite-capsule:el8/python-django
Affected
Red Hat Satellite 6
satellite:el8/python-django
Affected
Red Hat Storage 3
python-django
Will not fix
Red Hat Update Infrastructure 3 for Cloud Providers
python-django
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| RHUI 4 for RHEL 8 | python-django-0:3.2.18-1.0.1.el8ui | Fixed | RHSA-2023:2101 |
| Red Hat Satellite 6.13 for RHEL 8 | python-django-0:3.2.18-1.el8pc | Fixed | RHSA-2023:2097 |
| Red Hat Satellite 6.13 for RHEL 8 | python-django-0:3.2.18-1.el8pc | Fixed | RHSA-2023:2097 |
| Red Hat Ansible Automation Platform 2 | python-django | Affected | n/a |
| Red Hat Ceph Storage 3 | python-django | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-django | Out of support scope | n/a |
| Red Hat OpenStack Platform 16.1 | python-django20 | Will not fix | n/a |
| Red Hat OpenStack Platform 16.2 | python-django20 | Will not fix | n/a |
| Red Hat OpenStack Platform 17.0 | python-django | Will not fix | n/a |
| Red Hat Satellite 6 | satellite-capsule:el8/python-django | Affected | n/a |
| Red Hat Satellite 6 | satellite:el8/python-django | Affected | n/a |
| Red Hat Storage 3 | python-django | Will not fix | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | python-django | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (21)
- https://access.redhat.com/security/cve/CVE-2023-23969 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2166457 Issue Tracking
- https://docs.djangoproject.com/en/4.1/releases/security PatchVendor Advisory
- https://github.com/advisories/GHSA-q2jf-h9jm-m7p4 Advisory
- https://github.com/django/django/commit/4452642f193533e288a52c02efb5bbc766a68f95
- https://github.com/django/django/commit/8a7b22d4a623bcd95190d2f5a958472fb41e576d
- https://github.com/django/django/commit/8c660fb59239828583f17cdede3b64f208b8752c
- https://github.com/django/django/commit/9d7bd5a56b1ce0576e8e07a8001373576d277942
- https://github.com/django/django/commit/c7e0151fdf33e1b11d488b6f67b94fdf3a30614a
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2023-12.yaml
- https://groups.google.com/forum/#!forum/django-announce
- https://groups.google.com/forum/#%21forum/django-announce
- https://lists.debian.org/debian-lts-announce/2023/02/msg00000.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI
- https://nvd.nist.gov/vuln/detail/CVE-2023-23969
- https://security.netapp.com/advisory/ntap-20230302-0007
- https://www.cve.org/CVERecord?id=CVE-2023-23969
- https://www.djangoproject.com/weblog/2023/feb/01/security-releases Release NotesVendor Advisory
Change history (0)
No recorded changes yet.