Lucene search

K
ubuntuUbuntuUSN-6203-1
HistoryJul 05, 2023 - 12:00 a.m.

Django vulnerability

2023-07-0500:00:00
ubuntu.com
34
ubuntu
django
remote attacker
regular expressions
denial of service
high-level framework
python
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.6%

Releases

  • Ubuntu 23.04
  • Ubuntu 22.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • python-django - High-level Python web development framework

Details

Seokchan Yoon discovered that Django incorrectly handled certain regular
expressions. A remote attacker could possibly use this issue to cause
Django to consume resources, leading to a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu23.04noarchpython3-django< 3:3.2.18-1ubuntu0.3UNKNOWN
Ubuntu23.04noarchpython-django-doc< 3:3.2.18-1ubuntu0.3UNKNOWN
Ubuntu22.10noarchpython3-django< 3:3.2.15-1ubuntu1.4UNKNOWN
Ubuntu22.10noarchpython-django-doc< 3:3.2.15-1ubuntu1.4UNKNOWN
Ubuntu22.04noarchpython3-django< 2:3.2.12-2ubuntu1.7UNKNOWN
Ubuntu22.04noarchpython-django-doc< 2:3.2.12-2ubuntu1.7UNKNOWN
Ubuntu20.04noarchpython3-django< 2:2.2.12-1ubuntu0.18UNKNOWN
Ubuntu20.04noarchpython-django-doc< 2:2.2.12-1ubuntu0.18UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.6%