Resource management error in Django - CVE-2021-45115

 

Resource management error in Django - CVE-2021-45115

Published: January 4, 2022


Vulnerability identifier: #VU59179
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-45115
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources in UserAttributeSimilarityValidator when evaluating submitted password that were artificially large in relative to the comparison values. A remote attacker can pass specially crafted password to the application and perform a denial of service (DoS) attack.


Affected software

Django
Gentoo Linux
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Ubuntu
openEuler
Fedora
python3-django (Ubuntu package)
python-django (Ubuntu package)
python-Django1
python-Django
python-django
python-django-help
python3-Django
dev-python/django

How to mitigate CVE-2021-45115

Install updates from vendor's website.

Django - addressed in versions 2.2.26, 3.2.11, 4.0.1
python3-django (Ubuntu package) - addressed in versions 1:1.11.11-1ubuntu1.15, 2:2.2.12-1ubuntu0.9, 2:2.2.20-1ubuntu0.4, 2:2.2.24-1ubuntu1.2
python-django (Ubuntu package) - update to 1:1.11.11-1ubuntu1.15
python-Django1 - update to 1.11.29-3.30.1
python-Django - update to 1.11.29-3.33.1
python-django - addressed in versions 2.2.27-1, 2.2.27-2
python-django-help - addressed in versions 2.2.27-1, 2.2.27-2
python3-Django - addressed in versions 2.2.27-1, 2.2.27-2
python-django - addressed in versions 3.2.12-1.fc35, 4.0.2-1.fc36
dev-python/django - update to 5.2.1

External References

Related Security Bulletins