← All CVEs

CVE-2022-23833

high · 7.5

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

7.5
CVSS
49.5%
EPSS (exploit prob.)
99th
EPSS percentile
2022-02-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-835

Affected products

VendorProductAffected versions
djangoprojectdjango>= 2.2, < 2.2.27
djangoprojectdjango>= 3.2, < 3.2.12
djangoprojectdjango>= 4.0, < 4.0.2
fedoraprojectfedora34
fedoraprojectfedora35
debiandebian_linux11.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-23833