USN-6054-1: Django vulnerability
Published May 3, 2023
·Updated
Moataz Al-Sharida and nawaik discovered that Django incorrectly handled uploading multiple files using one form field. A remote attacker could possibly use this issue to bypass certain validations.
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/python3-django<3:3.2.18-1ubuntu0.1
3:3.2.18-1ubuntu0.1
Ubuntu Ubuntu=23.04
All of the following
ubuntu/python3-django<3:3.2.15-1ubuntu1.3
3:3.2.15-1ubuntu1.3
Ubuntu Ubuntu=22.10
All of the following
ubuntu/python3-django<2:3.2.12-2ubuntu1.6
2:3.2.12-2ubuntu1.6
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python3-django<2:2.2.12-1ubuntu0.17
2:2.2.12-1ubuntu0.17
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python3-django<1:1.11.11-1ubuntu1.21
1:1.11.11-1ubuntu1.21
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python-django<1:1.11.11-1ubuntu1.21
1:1.11.11-1ubuntu1.21
Ubuntu Ubuntu=18.04
Event History
May 3, 2023
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Django vulnerability?
The vulnerability ID is USN-6054-1.
2
What type of vulnerability is the Django vulnerability?
The Django vulnerability is related to uploading multiple files using one form field.
3
How can a remote attacker exploit the Django vulnerability?
A remote attacker could possibly bypass certain validations using this vulnerability.
4
Which versions of Python-Django are affected by the vulnerability?
The vulnerability affects versions 3:3.2.18-1ubuntu0.1, 3:3.2.15-1ubuntu1.3, 2:3.2.12-2ubuntu1.6, 2:2.2.12-1ubuntu0.17, and 1:1.11.11-1ubuntu1.21 of Python-Django.
5
How do I fix the Django vulnerability?
You can fix the vulnerability by updating the python3-django package to version 3:3.2.18-1ubuntu0.1 or higher.