CVE-2023-24580 PUBLISHED

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

EPSS 25.41% · 96.2th percentile

Risk Scores

EPSS Score
25.41%
96.2th percentile

Affected Products

VendorProductVersions
Bitnamidjango3.2.0, 4.0.0, 4.1.0
Bitnamidjango3.2.0, 4.0.0, 4.1.0

Timeline

References

Open in Interactive Console →