CVE-2022-23833

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

22 Nov 2023, 23:15

Type Values Removed Values Added
References
  • () https://github.com/django/django/commit/f9c7d48fdd6f198a6494a9202f90242f176e4fc9 -
  • () https://github.com/django/django/commit/d16133568ef9c9b42cb7a08bdf9ff3feec2e5468 -
  • () https://github.com/django/django/commit/c477b761804984c932704554ad35f78a2e230c6a -

07 Nov 2023, 03:44

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/', 'name': 'FEDORA-2022-e7fd530688', 'tags': ['Mailing List', 'Vendor Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://groups.google.com/forum/#!forum/django-announce', 'name': 'https://groups.google.com/forum/#!forum/django-announce', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/ -
  • () https://groups.google.com/forum/#%21forum/django-announce -

07 Nov 2022, 18:40

Type Values Removed Values Added
First Time Debian debian Linux
Debian
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
References (DEBIAN) https://www.debian.org/security/2022/dsa-5254 - (DEBIAN) https://www.debian.org/security/2022/dsa-5254 - Third Party Advisory

16 Oct 2022, 00:15

Type Values Removed Values Added
References
  • (DEBIAN) https://www.debian.org/security/2022/dsa-5254 -

22 Feb 2022, 10:18

Type Values Removed Values Added
CPE cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220221-0003/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220221-0003/ - Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/ - Mailing List, Vendor Advisory
First Time Fedoraproject fedora
Fedoraproject

21 Feb 2022, 10:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220221-0003/ -

11 Feb 2022, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/ -

07 Feb 2022, 20:31

Type Values Removed Values Added
CPE cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
First Time Djangoproject
Djangoproject django
CWE CWE-835
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (MISC) https://groups.google.com/forum/#!forum/django-announce - (MISC) https://groups.google.com/forum/#!forum/django-announce - Mailing List, Third Party Advisory
References (MISC) https://docs.djangoproject.com/en/4.0/releases/security/ - (MISC) https://docs.djangoproject.com/en/4.0/releases/security/ - Patch, Third Party Advisory
References (CONFIRM) https://www.djangoproject.com/weblog/2022/feb/01/security-releases/ - (CONFIRM) https://www.djangoproject.com/weblog/2022/feb/01/security-releases/ - Patch, Third Party Advisory

03 Feb 2022, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-03 02:15

Updated : 2023-12-10 14:09


NVD link : CVE-2022-23833

Mitre link : CVE-2022-23833

CVE.ORG link : CVE-2022-23833


JSON object : View

Products Affected

debian

  • debian_linux

djangoproject

  • django

fedoraproject

  • fedora
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')