First published: Mon Sep 04 2023(Updated: )
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Djangoproject Django | >=3.2<3.2.21 | |
Djangoproject Django | >=4.1<4.1.11 | |
Djangoproject Django | >=4.2<4.2.5 | |
Fedoraproject Fedora | =39 | |
pip/django | >=4.2<4.2.5 | 4.2.5 |
pip/django | >=4.1<4.1.11 | 4.1.11 |
pip/django | >=3.2<3.2.21 | 3.2.21 |
redhat/python-django | <4.2.5 | 4.2.5 |
redhat/python-django | <4.1.11 | 4.1.11 |
redhat/python-django | <3.2.21 | 3.2.21 |
ubuntu/python-django | <3.2.21<4.1.11<4.2.5 | 3.2.21 4.1.11 4.2.5 |
ubuntu/python-django | <2:2.2.12-1ubuntu0.19 | 2:2.2.12-1ubuntu0.19 |
ubuntu/python-django | <2:3.2.12-2ubuntu1.8 | 2:3.2.12-2ubuntu1.8 |
ubuntu/python-django | <3:3.2.18-1ubuntu0.4 | 3:3.2.18-1ubuntu0.4 |
ubuntu/python-django | <1:1.11.11-1ubuntu1.21+ | 1:1.11.11-1ubuntu1.21+ |
ubuntu/python-django | <3:4.2.4-1ubuntu1 | 3:4.2.4-1ubuntu1 |
debian/python-django | <=1:1.11.29-1~deb10u1<=2:2.2.28-1~deb11u2<=3:3.2.19-1+deb12u1 | 1:1.11.29-1+deb10u11 3:4.2.11-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-41164.
The severity level of CVE-2023-41164 is medium.
Software versions 4.2.5, 4.1.11, 3.2.21, 2:2.2.12-1ubuntu0.19, 2:3.2.12-2ubuntu1.8, 3:3.2.18-1ubuntu0.4, and 1:1.11.29-1+deb10u10 are affected by CVE-2023-41164.
To fix CVE-2023-41164, upgrade to version 4.2.5, 4.1.11, 3.2.21, 2:2.2.12-1ubuntu0.19, 2:3.2.12-2ubuntu1.8, 3:3.2.18-1ubuntu0.4, or 1:1.11.29-1+deb10u10 of python-django.
You can find more information about CVE-2023-41164 in the following references: [link1](https://www.openwall.com/lists/oss-security/2023/09/04/1), [link2](https://www.djangoproject.com/weblog/2023/sep/04/security-releases/), [link3](https://github.com/django/django/commit/3f41d6d62929dfe53eda8109b3b836f26645bdce).