CVE-2022-23833

Related Vulnerabilities: CVE-2022-23833  

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

Description

The MITRE CVE dictionary describes this issue as:

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

Additional Information

  • Bugzilla 2048778: CVE-2022-23833 django: Denial-of-service possibility in file uploads
  • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
  • FAQ: Frequently asked questions about CVE-2022-23833