https://seclists.org/oss-sec/2023/q4/199: Django: CVE-2023-46695: Potential denial of service vulnerability in UsernameField on Windows
Published Nov 1, 2023
·Updated
Affected Software
1 affected component
Django Software Foundation Django<=4.2.6, <=3.2.22
Frequently Asked Questions
1
What is the severity of CVE-2023-46695?
CVE-2023-46695 is classified as a potential denial of service vulnerability.
2
How do I fix CVE-2023-46695?
To mitigate CVE-2023-46695, you should upgrade to Django 4.2.7 or Django 3.2.23.
3
What impact does CVE-2023-46695 have on Django applications?
CVE-2023-46695 can lead to a denial of service condition in Django applications running on Windows.
4
Which versions of Django are affected by CVE-2023-46695?
CVE-2023-46695 affects all versions of Django prior to 4.2.7 and 3.2.23.
5
Is there a workaround for CVE-2023-46695?
There is no official workaround for CVE-2023-46695; updating to a patched version is recommended.