CVE-2023-23969: High severity djangoproject Django vulnerability
A flaw was found in python-django. The parsed values of the Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial of service vector via excessive memory usage if large header values are sent.
Other sources
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
The parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if large header values are sent.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2023-23969.
What is the severity of CVE-2023-23969?
The severity of CVE-2023-23969 is high.
How does CVE-2023-23969 affect Django?
CVE-2023-23969 affects Django versions 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6.
What is the potential impact of CVE-2023-23969?
The potential impact of CVE-2023-23969 is a denial-of-service vector via excessive memory usage.
How can I fix CVE-2023-23969?
To fix CVE-2023-23969, users should update Django to version 3.2.17, 4.0.9, or 4.1.6.