QID 995837

Date Published: 2023-11-06

QID 995837: Python (Pip) Security Update for django (GHSA-7h4p-27mh-hmrw)

In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.2 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Github security advisory GHSA-7h4p-27mh-hmrw for updates and patch information.
    Vendor References

    CVEs related to QID 995837

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7h4p-27mh-hmrw django URL Logo github.com/advisories/GHSA-7h4p-27mh-hmrw