CVE-2023-23969
01.02.2023, 19:15
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.Enginsight
Vendor | Product | Version |
---|---|---|
djangoproject | django | 3.2 ≤ 𝑥 < 3.2.17 |
djangoproject | django | 4.0 ≤ 𝑥 < 4.0.9 |
djangoproject | django | 4.1 ≤ 𝑥 < 4.1.6 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python-django |
|
References