CVE-2023-23969
CVSS V2 None
CVSS V3 None
Description
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
Overview
- CVE ID
- CVE-2023-23969
- Assigner
- cve@mitre.org
- Vulnerability Status
- Modified
- Published Version
- 2023-02-01T19:15:08
- Last Modified Date
- 2023-04-28T04:15:37
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | 1 | OR | 3.2 | 3.2.17 |
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | 1 | OR | 4.0 | 4.0.9 |
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | 1 | OR | 4.1 | 4.1.6 |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | 1 | OR |
References
Reference URL | Reference Tags |
---|---|
https://docs.djangoproject.com/en/4.1/releases/security/ | Patch Vendor Advisory |
https://groups.google.com/forum/#!forum/django-announce | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/02/msg00000.html | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK/ | |
https://security.netapp.com/advisory/ntap-20230302-0007/ | |
https://www.djangoproject.com/weblog/2023/feb/01/security-releases/ | Release Notes Vendor Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-23969 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23969 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 07:05:26 | Added to TrackCVE | |||
2023-04-17 07:05:29 | Weakness Enumeration | new | ||
2023-04-28 05:03:48 | 2023-04-28T04:15:37 | CVE Modified Date | updated | |
2023-04-28 05:03:49 | References | updated |