Vulnerability CVE-2023-36053: Information

Description

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: July 3, 2023
Modified: April 20, 2024
Error type identifier: CWE-1333

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
python3-module-djangosisyphus3.2.20-alt14.2.11-alt1ALT-PU-2023-4362-1324744Fixed
python3-module-djangosisyphus_e2k3.2.20-alt14.2.11-alt1ALT-PU-2023-4378-1-Fixed
python3-module-djangosisyphus_riscv643.2.20-alt14.2.11-alt1ALT-PU-2023-4376-1-Fixed
python3-module-djangop103.2.20-alt13.2.23-alt1ALT-PU-2023-4363-3324745Fixed
python3-module-djangop10_e2k3.2.20-alt13.2.23-alt1ALT-PU-2023-5091-1-Fixed
python3-module-djangoc10f13.2.20-alt13.2.25-alt1ALT-PU-2023-4380-2324750Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      4.2
      End excliding
      4.2.3

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      4.0
      End excliding
      4.1.10

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      3.2
      End excliding
      3.2.20

      Configuration 2

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*