CVE-2023-41164: Django: CVE-2023-41164: Potential denial of service vulnerability in django.utils.encoding.uri_to_iri()
django.utils.encoding.uritoiri() was subject to potential denial of service attack via certain inputs with a very large number of Unicode characters.
https://www.djangoproject.com/weblog/2023/sep/04/security-releases/
Other sources
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uritoiri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
— Ubuntu
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this potential denial of service vulnerability?
The vulnerability ID is CVE-2023-41164.
What is the severity level of CVE-2023-41164?
The severity level of CVE-2023-41164 is medium.
Which software versions are affected by CVE-2023-41164?
Software versions 4.2.5, 4.1.11, 3.2.21, 2:2.2.12-1ubuntu0.19, 2:3.2.12-2ubuntu1.8, 3:3.2.18-1ubuntu0.4, and 1:1.11.29-1+deb10u10 are affected by CVE-2023-41164.
How can I fix CVE-2023-41164?
To fix CVE-2023-41164, upgrade to version 4.2.5, 4.1.11, 3.2.21, 2:2.2.12-1ubuntu0.19, 2:3.2.12-2ubuntu1.8, 3:3.2.18-1ubuntu0.4, or 1:1.11.29-1+deb10u10 of python-django.
Where can I find more information about CVE-2023-41164?
You can find more information about CVE-2023-41164 in the following references: [link1](https://www.openwall.com/lists/oss-security/2023/09/04/1), [link2](https://www.djangoproject.com/weblog/2023/sep/04/security-releases/), [link3](https://github.com/django/django/commit/3f41d6d62929dfe53eda8109b3b836f26645bdce).