CVE Vulnerabilities

CVE-2022-41323

Published: Oct 16, 2022 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject 3.2 (including) 3.2.16 (excluding)
Django Djangoproject 4.0 (including) 4.0.8 (excluding)
Django Djangoproject 4.1 (including) 4.1.2 (excluding)
Red Hat Satellite 6.13 for RHEL 8 RedHat python-django-0:3.2.18-1.el8pc *
Red Hat Satellite 6.13 for RHEL 8 RedHat python-django-0:3.2.18-1.el8pc *
RHUI 4 for RHEL 8 RedHat python-django-0:3.2.16-1.0.1.el8ui *
Python-django Ubuntu devel *
Python-django Ubuntu focal *
Python-django Ubuntu jammy *
Python-django Ubuntu kinetic *
Python-django Ubuntu trusty *
Python-django Ubuntu xenial *

References