CVE-2022-41323: High severity djangoproject Django vulnerability
A denial of service flaw was discovered in Django. This issue occurs when incorrectly handling certain internationalized URLs. A malicious attacker could use this issue to cause a crash, resulting in a denial of service.
Other sources
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-djangoto a version that resolves this vulnerability.Fixed in 0:3.2.18-1.el8 - Upgrade
Upgrade
redhat/python-djangoto a version that resolves this vulnerability.Fixed in 0:3.2.16-1.0.1.el8 - Upgrade
Upgrade
debian/python-djangoto a version that resolves this vulnerability.Fixed in 1:1.11.29-1~deb10u1Fixed in 1:1.11.29-1+deb10u10Fixed in 2:2.2.28-1~deb11u2Fixed in 3:3.2.19-1+deb12u1Fixed in 3:3.2.21-1Fixed in 3:4.2.8-1 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 3.2.16 - Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 3.2.16 - Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 4.1.2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-41323?
The severity of CVE-2022-41323 is high.
How do I fix CVE-2022-41323?
To fix CVE-2022-41323, update Django to version 4.1.2, 4.0.8, or 3.2.16 depending on your current version.
What is the impact of CVE-2022-41323?
CVE-2022-41323 can be exploited by a malicious attacker to cause a crash, resulting in a denial of service.
Where can I find more information about CVE-2022-41323?
You can find more information about CVE-2022-41323 on the NIST NVD website, Django's GitHub repository, and the Django website.
What is the CWE ID of CVE-2022-41323?
The CWE ID of CVE-2022-41323 is 400.