CVE-2023-31047
Summary
| CVE | CVE-2023-31047 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-07 02:15:00 UTC |
| Updated | 2023-11-07 04:14:00 UTC |
| Description | In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181774 Debian Security Update for python-django (DLA 3415-1)
- 182538 Debian Security Update for python-django (CVE-2023-31047)
- 199318 Ubuntu Security Notification for Django Vulnerability (USN-6054-1)
- 199508 Ubuntu Security Notification for Django Vulnerability (USN-6054-2)
- 242347 Red Hat Update for Satellite 6.14 (RHSA-2023:6818)
- 242363 Red Hat Update for Satellite 6.13.5 (RHSA-2023:5931)
- 283984 Fedora Security Update for python (FEDORA-2023-8f9d949dbc)
- 284143 Fedora Security Update for python (FEDORA-2023-0d20d09f2d)
- 296100 Oracle Solaris 11.4 Support Repository Update (SRU) 58.144.3 Missing (CPUAPR2023)
- 6000222 Debian Security Update for python-django (DSA 5465-1)
- 691161 Free Berkeley Software Distribution (FreeBSD) Security Update for django (d55e1b4d-eadc-11ed-9cc0-080027de9982)
- 961065 Rocky Linux Security Update for Satellite (RLSA-2023:6818)