CVE-2022-23833: High severity django vulnerability
A flaw was found in Django. The issue occurs when passing certain inputs to multipart forms, resulting in an infinite loop when parsing files.
Other sources
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-23833?
CVE-2022-23833 is a vulnerability discovered in Django.
What is the severity of CVE-2022-23833?
CVE-2022-23833 has a severity level of high.
How does CVE-2022-23833 affect Django?
CVE-2022-23833 affects Django versions 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.
What is the solution for CVE-2022-23833?
To fix CVE-2022-23833, you need to update Django to version 2.2.27, 3.2.12, or 4.0.2.
Where can I find more information about CVE-2022-23833?
You can find more information about CVE-2022-23833 in the references provided: [reference 1](https://bugzilla.redhat.com/show_bug.cgi/attachment.cgi?id=1858150), [reference 2](https://bugzilla.redhat.com/show_bug.cgi/attachment.cgi?id=1858150&action=edit), [reference 3](https://bugzilla.redhat.com/show_bug.cgi/attachment.cgi?id=1858151).