Resource exhaustion in Django - CVE-2023-46695
Published: November 1, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources during NFKC normalization. A remote attacker can pass a very large number of Unicode characters to "django.contrib.auth.forms.UsernameField" and perform a denial of service (DoS) attack.
The vulnerability affects Windows installations only.
Affected software
openEuler
Anolis OS
python-django
python-django-help
python3-Django
python3-django
python3-django-bash-completion
python3-django-doc
Cloud Pak for Network Automation
How to mitigate CVE-2023-46695
python-django - update to 2.2.27-9
python-django-help - update to 2.2.27-9
python3-Django - update to 2.2.27-9
Cloud Pak for Network Automation - update to 2.6.5
python3-django - update to 4.2.7-1
python3-django-bash-completion - update to 4.2.7-1
python3-django-doc - update to 4.2.7-1