Lucene search

K
githubGitHub Advisory DatabaseGHSA-QMF9-6JQF-J8FQ
HistoryNov 02, 2023 - 6:30 a.m.

Django potential denial of service vulnerability in UsernameField on Windows

2023-11-0206:30:25
CWE-400
CWE-770
GitHub Advisory Database
github.com
30
django
denial of service
vulnerability
usernamefield
windows
nfkc normalization

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

28.0%

An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.

Affected configurations

Vulners
Node
djangoRange4.2a14.2.7
OR
djangoRange4.1a14.1.13
OR
djangoRange3.2a13.2.23
VendorProductVersionCPE
*django*cpe:2.3:a:*:django:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

28.0%