CVE-2023-31047
ADVISORY - githubSummary
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.
EPSS Score: 0.00063 (0.200)
Common Weakness Enumeration (CWE)
ADVISORY - github
Improper Input Validation
ADVISORY - gitlab
ADVISORY - redhat
Improper Input Validation
PypA
CREATED
UPDATED
ADVISORY ID
PYSEC-2023-61
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
---|---|---|---|---|---|
django | pypi | - | - | >=4.0,<4.1.9 | 4.1.9 |
django | pypi | - | - | >=3.2,<3.2.19 | 3.2.19 |
django | pypi | - | - | >=4.2,<4.2.1 | 4.2.1 |
Severity and metrics
No CVSS data available from this advisory.
NIST
CVSS SCORE
9.8criticalGitHub
CREATED
UPDATED
ADVISORY IDGHSA-r3xc-prgr-mg9p
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
9.3criticalDebian
CREATED
UPDATED
ADVISORY IDCVE-2023-31047
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2023-31047
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
9.8lowBitnami
CREATED
UPDATED
ADVISORY ID
BIT-2023-31047
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AcriticalBitnami
CREATED
UPDATED
ADVISORY ID
BIT-django-2023-31047
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
9.8criticalRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2023-31047
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
6.5mediumRocky
CREATED
UPDATED
ADVISORY IDRLSA-2023:6818
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-