MGASA-2023-0165

Source
https://advisories.mageia.org/MGASA-2023-0165.html
Import Source
https://advisories.mageia.org/MGASA-2023-0165.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2023-0165
Related
Published
2023-05-16T19:17:40Z
Modified
2023-05-16T18:08:58Z
Summary
Updated python-django packages fix security vulnerability
Details

Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack. (CVE-2023-24580) Bypass of validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise. (CVE-2023-31047)

References
Credits

Affected packages

Mageia:8 / python-django

Package

Name
python-django
Purl
pkg:rpm/mageia/python-django?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.18-1.mga8

Ecosystem specific

{
    "section": "core"
}