CVE-2023-36053
Summary
| CVE | CVE-2023-36053 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-03 13:15:00 UTC |
| Updated | 2023-11-15 03:18:00 UTC |
| Description | In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs. |
Risk And Classification
Problem Types: CWE-1333
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 12.0 | All | All | All |
| Application | Djangoproject | Django | All | All | All | All |
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Operating System | Fedoraproject | Fedora | 38 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-5465-1 python-django | DEBIAN | www.debian.org | |
| Redirecting to Google Groups | groups.google.com | ||
| [SECURITY] Fedora 37 Update: python-asgiref-3.5.2-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Django security releases issued: 4.2.3, 4.1.10, and 3.2.20 | Weblog | Django | CONFIRM | www.djangoproject.com | |
| [SECURITY] Fedora 38 Update: python-django-4.1.12-1.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Redirecting to Google Groups | MISC | groups.google.com | |
| [SECURITY] Fedora 38 Update: python-django-4.1.12-1.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] [DLA 3500-1] python-django security update | MLIST | lists.debian.org | Mailing List |
| [SECURITY] Fedora 37 Update: python-asgiref-3.5.2-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Archive of security issues | Django documentation | Django | MISC | docs.djangoproject.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199450 Ubuntu Security Notification for Django Vulnerability (USN-6203-1)
- 199601 Ubuntu Security Notification for Django Vulnerability (USN-6203-2)
- 242347 Red Hat Update for Satellite 6.14 (RHSA-2023:6818)
- 242363 Red Hat Update for Satellite 6.13.5 (RHSA-2023:5931)
- 242874 Red Hat Update for OpenStack Platform 17.1 (RHSA-2024:0212)
- 284628 Fedora Security Update for python (FEDORA-2023-cc023fabb7)
- 284653 Fedora Security Update for python (FEDORA-2023-9d36d373f1)
- 296103 Oracle Solaris 11.4 Support Repository Update (SRU) 61.151.2 Missing (CPUJUL2023)
- 6000129 Debian Security Update for python-django (DLA 3500-1)
- 6000222 Debian Security Update for python-django (DSA 5465-1)
- 691203 Free Berkeley Software Distribution (FreeBSD) Security Update for django (4ee7fa77-19a6-11ee-8a05-080027eda32c)
- 961065 Rocky Linux Security Update for Satellite (RLSA-2023:6818)