CVE-2019-14235: High severity django vulnerability
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uritoiri could lead to significant memory usage due to a recursion when repercent-encoding invalid UTF-8 octet sequences.
Other sources
If passed certain inputs, :func:django.utils.encoding.uritoiri could lead to significant memory usage due to excessive recursion when re-percent-encoding invalid UTF-8 octet sequences.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-14235?
CVE-2019-14235 is a vulnerability discovered in Django versions 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4.
What is the severity of CVE-2019-14235?
The severity of CVE-2019-14235 is high, with a severity value of 7.5.
How does CVE-2019-14235 affect the Django software?
If certain inputs are passed, the vulnerability in django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid UTF-8 octet sequences.
Which software versions are affected by CVE-2019-14235?
Django versions 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4 are affected by CVE-2019-14235.
How can I fix CVE-2019-14235?
To fix CVE-2019-14235, you should update your Django software to version 1.11.23, 2.1.11, or 2.2.4.