CVE-2023-46695
Dashboard / Vulnerabilities / CVE-2023-46695
CVE-2023-46695
Summary:
Details: An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
References: https://docs.djangoproject.com/en/4.2/releases/security/, https://groups.google.com/forum/#%21forum/django-announce, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46695.json, https://nvd.nist.gov/vuln/detail/CVE-2023-46695, https://security.netapp.com/advisory/ntap-20231214-0001/, https://www.djangoproject.com/weblog/2023/nov/01/security-releases/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
