CVE-2023-36053: High severity djangoproject Django vulnerability
EmailValidator and URLValidator were subject to potential regular expression denial of service attack via a very large number of domain name labels of emails and URLs.
Affected versions: Django main development branch, Django 4.2, Django 4.1, Django 3.2
Other sources
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 4.2.3Fixed in 4.1.10Fixed in 3.2.20 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 2:2.2.12-1ubuntu0.18 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 2:3.2.12-2ubuntu1.7 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 3:3.2.15-1ubuntu1.4 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 3:3.2.18-1ubuntu0.3 - Upgrade
Upgrade
ubuntu/python-djangoto a version that resolves this vulnerability.Fixed in 1:1.11.11-1ubuntu1.21+ - Upgrade
Upgrade
debian/python-djangoto a version that resolves this vulnerability.Fixed in 1:1.11.29-1+deb10u10Fixed in 2:2.2.28-1~deb11u2Fixed in 3:3.2.19-1+deb12u1Fixed in 3:3.2.21-1Fixed in 3:4.2.8-1 - Upgrade
Upgrade
pip/Djangoto a version that resolves this vulnerability.Fixed in 4.2.3 - Upgrade
Upgrade
pip/Djangoto a version that resolves this vulnerability.Fixed in 4.1.10 - Upgrade
Upgrade
pip/Djangoto a version that resolves this vulnerability.Fixed in 3.2.20 - Upgrade
Upgrade
redhat/python-djangoto a version that resolves this vulnerability.Fixed in 4.2.3 - Upgrade
Upgrade
redhat/python-djangoto a version that resolves this vulnerability.Fixed in 4.1.10 - Upgrade
Upgrade
redhat/python-djangoto a version that resolves this vulnerability.Fixed in 3.2.20 - Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 3.2.20 - Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 4.1.10 - Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 4.2.3
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-36053.
What is the severity level of CVE-2023-36053?
The severity level of CVE-2023-36053 is high.
Which versions of Django are affected by CVE-2023-36053?
Django versions 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3 are affected by CVE-2023-36053.
What is the impact of CVE-2023-36053?
CVE-2023-36053 can lead to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs in Django applications.
How can I mitigate the vulnerability CVE-2023-36053?
To mitigate CVE-2023-36053, it is recommended to update Django to versions 3.2.20 or later, 4.1.10 or later, or 4.2.3 or later.