CVE-2023-24580
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-24580
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-24580.html
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:2097
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rocky | 8 | fixed | |
| sles | affected | | |
| debian | bookworm | fixed | 3:3.2.18-1 |
| debian | bullseye | fixed | 2:2.2.28-1~deb11u2 |
| debian | forky | fixed | 3:3.2.18-1 |
| debian | sid | fixed | 3:3.2.18-1 |
| debian | trixie | fixed | 3:3.2.18-1 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-24580
- https://github.com/django/django/commit/628b33a854a9c68ec8a0c51f382f304a0044ec92
- https://github.com/django/django/commit/83f1ea83e4553e211c1c5a0dfc197b66d4e50432
- https://github.com/django/django/commit/a665ed5179f5bbd3db95ce67286d0192eff041d8
- https://www.djangoproject.com/weblog/2023/feb/14/security-releases
- https://security.netapp.com/advisory/ntap-20230316-0006
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJB6FUBBLVKKG655UMTLQNN6UQ6EDLSP
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZS4G6NSZWPTVXMMZHJOJVQEPL3QTO77
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FKYVMMR7RPM6AHJ2SBVM2LO6D3NGFY7B
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJB6FUBBLVKKG655UMTLQNN6UQ6EDLSP
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VZS4G6NSZWPTVXMMZHJOJVQEPL3QTO77
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FKYVMMR7RPM6AHJ2SBVM2LO6D3NGFY7B
- https://lists.debian.org/debian-lts-announce/2023/02/msg00023.html
- https://groups.google.com/forum/#%21forum/django-announce
- https://groups.google.com/forum/#!forum/django-announce
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2023-13.yaml
- https://github.com/django/django
- https://docs.djangoproject.com/en/4.1/releases/security
- http://www.openwall.com/lists/oss-security/2023/02/14/1
- https://docs.djangoproject.com/en/4.1/releases/security/
- https://www.djangoproject.com/weblog/2023/feb/14/security-releases/
Verify integrity in audit chain (admin only). AS-IS.