CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:4.2:-:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:4.2:b1:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:4.2:rc1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

History

07 Nov 2023, 04:14

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNEHD6N435OE2XUFGDAAVAXSYWLCUBFD/', 'name': 'FEDORA-2023-8f9d949dbc', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A45VKTUVQ2BN6D5ZLZGCM774R6QGFOHW/', 'name': 'FEDORA-2023-0d20d09f2d', 'tags': ['Issue Tracking', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://groups.google.com/forum/#!forum/django-announce', 'name': 'https://groups.google.com/forum/#!forum/django-announce', 'tags': ['Mailing List'], 'refsource': 'MISC'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A45VKTUVQ2BN6D5ZLZGCM774R6QGFOHW/ -
  • () https://groups.google.com/forum/#%21forum/django-announce -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DNEHD6N435OE2XUFGDAAVAXSYWLCUBFD/ -

09 Jun 2023, 08:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230609-0008/ -

16 May 2023, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNEHD6N435OE2XUFGDAAVAXSYWLCUBFD/ -

15 May 2023, 16:43

Type Values Removed Values Added
References (CONFIRM) https://www.djangoproject.com/weblog/2023/may/03/security-releases/ - (CONFIRM) https://www.djangoproject.com/weblog/2023/may/03/security-releases/ - Vendor Advisory
References (MISC) https://docs.djangoproject.com/en/4.2/releases/security/ - (MISC) https://docs.djangoproject.com/en/4.2/releases/security/ - Vendor Advisory
References (MISC) https://groups.google.com/forum/#!forum/django-announce - (MISC) https://groups.google.com/forum/#!forum/django-announce - Mailing List
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A45VKTUVQ2BN6D5ZLZGCM774R6QGFOHW/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A45VKTUVQ2BN6D5ZLZGCM774R6QGFOHW/ - Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:4.2:-:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:4.2:b1:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:4.2:rc1:*:*:*:*:*:*
CWE CWE-20
First Time Djangoproject django
Djangoproject
Fedoraproject
Fedoraproject fedora
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

11 May 2023, 05:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A45VKTUVQ2BN6D5ZLZGCM774R6QGFOHW/ -

07 May 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-07 02:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-31047

Mitre link : CVE-2023-31047

CVE.ORG link : CVE-2023-31047


JSON object : View

Products Affected

djangoproject

  • django

fedoraproject

  • fedora
CWE
CWE-20

Improper Input Validation