mirror of
https://github.com/django/django.git
synced 2025-10-24 06:06:09 +00:00
Fixed CVE-2022-23833 -- Fixed DoS possiblity in file uploads.
Thanks Alan Ryan for the report and initial patch.
This commit is contained in:
@@ -15,3 +15,9 @@ posing an XSS attack vector.
|
||||
In order to avoid this vulnerability, ``{% debug %}`` no longer outputs an
|
||||
information when the ``DEBUG`` setting is ``False``, and it ensures all context
|
||||
variables are correctly escaped when the ``DEBUG`` setting is ``True``.
|
||||
|
||||
CVE-2022-23833: Denial-of-service possibility in file uploads
|
||||
=============================================================
|
||||
|
||||
Passing certain inputs to multipart forms could result in an infinite loop when
|
||||
parsing files.
|
||||
|
||||
@@ -15,3 +15,9 @@ posing an XSS attack vector.
|
||||
In order to avoid this vulnerability, ``{% debug %}`` no longer outputs an
|
||||
information when the ``DEBUG`` setting is ``False``, and it ensures all context
|
||||
variables are correctly escaped when the ``DEBUG`` setting is ``True``.
|
||||
|
||||
CVE-2022-23833: Denial-of-service possibility in file uploads
|
||||
=============================================================
|
||||
|
||||
Passing certain inputs to multipart forms could result in an infinite loop when
|
||||
parsing files.
|
||||
|
||||
@@ -18,6 +18,12 @@ In order to avoid this vulnerability, ``{% debug %}`` no longer outputs an
|
||||
information when the ``DEBUG`` setting is ``False``, and it ensures all context
|
||||
variables are correctly escaped when the ``DEBUG`` setting is ``True``.
|
||||
|
||||
CVE-2022-23833: Denial-of-service possibility in file uploads
|
||||
=============================================================
|
||||
|
||||
Passing certain inputs to multipart forms could result in an infinite loop when
|
||||
parsing files.
|
||||
|
||||
Bugfixes
|
||||
========
|
||||
|
||||
|
||||
Reference in New Issue
Block a user