摘要:
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
安全等级: Low
公告ID: KylinSec-SA-2022-2593
发布日期: 2022年11月11日
关联CVE: CVE-2022-41323
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2022-41323 | KY3.4-4A | python-django | Unaffected |
CVE-2022-41323 | KY3.4-5 | python-django | Unaffected |
CVE-2022-41323 | KY3.5.1 | python-django | Unaffected |