ZeroHour

CVE-2022-23833

CVSS 3.1
7.5 high
EPSS
50%p99
Published
()
Modified
Description

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

Vendors
djangoprojectfedoraprojectdebian
Products
django, fedora, debian linux
Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.