Bug 2169402 (CVE-2023-24580)

Summary: CVE-2023-24580 python-django: Potential denial-of-service vulnerability in file uploads
Product: [Other] Security Response Reporter: ybuenos
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: adudiak, amctagga, aoconnor, apevec, bbuckingham, bcoca, bcourt, bniver, btotty, cwelton, davidn, eglynn, ehelms, epacific, flucifre, gmeno, gtanzill, jcammara, jhardy, jjoyce, jneedle, jobarker, jsherril, kshier, lhh, lzap, mabashia, mbenjamin, mburns, mgarciac, mhackett, mhulan, mminar, nmoumoul, orabin, osapryki, pcreech, rbiba, rchan, rhos-maint, security-response-team, simaishi, smcdonal, sostapov, spower, sskracic, stcannon, teagle, tfister, vereddy, yguenane, zsadeh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: python-django 4.1.7, python-django 4.0.10, python-django 3.2.18 Doc Type: If docs needed, set a value
Doc Text:
A memory exhaustion flaw was found in the python-django package. This issue occurs when passing certain inputs, leading to a system crash and denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-05-03 23:16:35 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2169424, 2169431, 2169644, 2169645, 2169646, 2169647, 2169742, 2169743, 2169744, 2169745, 2169746, 2172889    
Bug Blocks: 2167773    

Description ybuenos 2023-02-13 14:21:15 UTC
Passing certain inputs to multipart forms could result in too many open files or memory exhaustion, and provide a potential vector for a denial-of-service attack.

Comment 7 ybuenos 2023-02-14 14:44:20 UTC
Created python-django tracking bugs for this issue:

Affects: fedora-36 [bug 2169743]
Affects: fedora-37 [bug 2169745]


Created python-django3 tracking bugs for this issue:

Affects: epel-8 [bug 2169742]
Affects: fedora-36 [bug 2169744]
Affects: fedora-37 [bug 2169746]

Comment 11 errata-xmlrpc 2023-05-03 13:20:25 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.13 for RHEL 8

Via RHSA-2023:2097 https://access.redhat.com/errata/RHSA-2023:2097

Comment 12 errata-xmlrpc 2023-05-03 14:55:59 UTC
This issue has been addressed in the following products:

  RHUI 4 for RHEL 8

Via RHSA-2023:2101 https://access.redhat.com/errata/RHSA-2023:2101

Comment 13 Product Security DevOps Team 2023-05-03 23:16:31 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2023-24580

Comment 14 errata-xmlrpc 2023-08-21 17:04:50 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.4 for RHEL 8
  Red Hat Ansible Automation Platform 2.4 for RHEL 9

Via RHSA-2023:4692 https://access.redhat.com/errata/RHSA-2023:4692