Vulnerability CVE-2023-46695: Information

Description

An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Nov. 2, 2023
Modified: Dec. 14, 2023
Error type identifier: CWE-770

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
python3-module-djangosisyphus4.2.8-alt14.2.11-alt1ALT-PU-2023-8342-2337270Fixed
python3-module-djangosisyphus_e2k4.2.8-alt14.2.11-alt1ALT-PU-2023-8358-1-Fixed
python3-module-djangosisyphus_riscv644.2.8-alt14.2.11-alt1ALT-PU-2023-8350-1-Fixed
python3-module-djangosisyphus_loongarch644.2.8-alt14.2.11-alt1ALT-PU-2023-8366-1-Fixed
python3-module-djangop103.2.23-alt13.2.23-alt1ALT-PU-2023-8343-3337271Fixed
python3-module-djangop10_e2k3.2.23-alt13.2.23-alt1ALT-PU-2023-8385-1-Fixed
python3-module-djangoc10f13.2.25-alt13.2.25-alt1ALT-PU-2024-3676-2342286Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      4.2.
      End excliding
      4.2.7

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      4.1
      End excliding
      4.1.13

      cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
      Start including
      3.2
      End excliding
      3.2.23