CVE-2022-23833
Summary
| CVE | CVE-2022-23833 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-03 02:15:00 UTC |
| Updated | 2023-11-22 23:15:00 UTC |
| Description | An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [3.2.x] Fixed CVE-2022-23833 -- Fixed DoS possiblity in file uploads. · django/django@d161335 · GitHub |
|
github.com |
|
| [SECURITY] Fedora 35 Update: python-django-3.2.12-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Redirecting to Google Groups |
|
groups.google.com |
|
| February 2022 Django Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Redirecting to Google Groups |
MISC |
groups.google.com |
|
| [4.0.x] Fixed CVE-2022-23833 -- Fixed DoS possiblity in file uploads. · django/django@f9c7d48 · GitHub |
|
github.com |
|
| Archive of security issues | Django documentation | Django |
MISC |
docs.djangoproject.com |
|
| [SECURITY] Fedora 35 Update: python-django-3.2.12-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Django security releases issued: 4.0.2, 3.2.12, and 2.2.27 | Weblog | Django |
CONFIRM |
www.djangoproject.com |
|
| [2.2.x] Fixed CVE-2022-23833 -- Fixed DoS possiblity in file uploads. · django/django@c477b76 · GitHub |
|
github.com |
|
| Debian -- Security Information -- DSA-5254-1 python-django |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179049 Debian Security Update for python-django (DLA 2906-1)
- 181137 Debian Security Update for python-django (DSA 5254-1)
- 181236 Debian Security Update for python-django (DLA 3191-1)
- 183845 Debian Security Update for python-django (CVE-2022-23833)
- 198652 Ubuntu Security Notification for Django Vulnerabilities (USN-5269-1)
- 240566 Red Hat Update for Satellite 6.11 Release (RHSA-2022:5498)
- 240972 Red Hat Update for OpenStack Platform 16.1.9 (RHSA-2022:8872)
- 240979 Red Hat Update for OpenStack Platform 16.2.4 (RHSA-2022:8853)
- 282363 Fedora Security Update for python (FEDORA-2022-e7fd530688)
- 296057 Oracle Solaris 11.4 Support Repository Update (SRU) 44.113.4 Missing (bulletinapr2022)
- 502340 Alpine Linux Security Update for py3-django
- 960505 Rocky Linux Security Update for Satellite (RLSA-2022:5498)