Resource exhaustion in Django - CVE-2023-24580
Published: February 16, 2023
Vulnerability identifier: #VU72330
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24580
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can certain inputs to multipart forms, trigger memory exhaustion and perform a denial of service (DoS) attack.
Affected software
Django
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Fedora
Oracle Solaris
Ubuntu
openEuler
Ansible Automation Platform
Red Hat Update Infrastructure (RHUI)
Red Hat Satellite
python3-django (Ubuntu package)
python-django (Ubuntu package)
python-Django1
python-Django
python3-Django
python-django-help
python-django
python-django (Debian package)
python-django3
automation-controller (Red Hat package)
dev-python/django
Cloud Pak for Network Automation
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Fedora
Oracle Solaris
Ubuntu
openEuler
Ansible Automation Platform
Red Hat Update Infrastructure (RHUI)
Red Hat Satellite
python3-django (Ubuntu package)
python-django (Ubuntu package)
python-Django1
python-Django
python3-Django
python-django-help
python-django
python-django (Debian package)
python-django3
automation-controller (Red Hat package)
dev-python/django
Cloud Pak for Network Automation
How to mitigate CVE-2023-24580
Install updates from vendor's website.
Django - addressed in versions 3.2.18, 4.0.10, 4.1.7
python3-django (Ubuntu package) - addressed in versions 1:1.11.11-1ubuntu1.20, 2:2.2.12-1ubuntu0.16, 2:3.2.12-2ubuntu1.5, 3:3.2.15-1ubuntu1.2
python-django (Ubuntu package) - update to 1:1.11.11-1ubuntu1.20
python-Django1 - update to 1.11.29-3.44.1
python-Django - update to 1.11.29-3.45.1
python3-Django - update to 2.2.27-4
python-django-help - update to 2.2.27-4
python-django - update to 2.2.27-4
python-django (Debian package) - addressed in versions 2:2.2.28-1~deb11u2, 3:3.2.19-1+deb12u1
Cloud Pak for Network Automation - update to 2.4.5
python-django3 - addressed in versions 3.2.18-1.el8, 3.2.18-1.fc36, 3.2.18-1.fc37, 3.2.18-1.fc38
python-django - addressed in versions 4.0.10-1.fc37, 4.0.10-1.fc38
Red Hat Update Infrastructure (RHUI) - update to 4.4.0
automation-controller (Red Hat package) - addressed in versions 4.4.2-1.el8ap, 4.4.2-1.el9ap
dev-python/django - update to 5.2.1
Red Hat Satellite - update to 6.13
python3-django (Ubuntu package) - addressed in versions 1:1.11.11-1ubuntu1.20, 2:2.2.12-1ubuntu0.16, 2:3.2.12-2ubuntu1.5, 3:3.2.15-1ubuntu1.2
python-django (Ubuntu package) - update to 1:1.11.11-1ubuntu1.20
python-Django1 - update to 1.11.29-3.44.1
python-Django - update to 1.11.29-3.45.1
python3-Django - update to 2.2.27-4
python-django-help - update to 2.2.27-4
python-django - update to 2.2.27-4
python-django (Debian package) - addressed in versions 2:2.2.28-1~deb11u2, 3:3.2.19-1+deb12u1
Cloud Pak for Network Automation - update to 2.4.5
python-django3 - addressed in versions 3.2.18-1.el8, 3.2.18-1.fc36, 3.2.18-1.fc37, 3.2.18-1.fc38
python-django - addressed in versions 4.0.10-1.fc37, 4.0.10-1.fc38
Red Hat Update Infrastructure (RHUI) - update to 4.4.0
automation-controller (Red Hat package) - addressed in versions 4.4.2-1.el8ap, 4.4.2-1.el9ap
dev-python/django - update to 5.2.1
Red Hat Satellite - update to 6.13
External References
Related Security Bulletins
- Denial of service in Django
- Ubuntu update for python-django
- SUSE update for python-Django
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Red Hat Update Infrastructure (RHUI)
- Multiple vulnerabilities in Red Hat Satellite 6.13
- SUSE update for python-Django1
- Debian update for python-django
- Fedora 37 update for python-django3
- Fedora 36 update for python-django3
- Fedora EPEL 8 update for python-django3
- Fedora 38 update for python-django3
- Fedora 38 update for python-django
- Fedora 37 update for python-django
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4 for RHEL 9
- openEuler update for python-django
- Gentoo update for Django