Bug 7156 - [Anolis OS 23] Bugfix for CVE-2023-36053
Summary: [Anolis OS 23] Bugfix for CVE-2023-36053
Status: RESOLVED FIXED
Alias: None
Product: Anolis OS 23
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: unspecified
Hardware: All Linux
: P2-High S2-major
Target Milestone: ---
Assignee: happy_orange
QA Contact: bolong_tbl
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-11-06 20:22 UTC by 小龙
Modified: 2023-11-06 20:23 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-11-06 20:22:03 UTC
Description:
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

Broken commit info:

Bugfix commit info:
https://github.com/django/django/commit/ad0410ec4f458aa39803e5f6b9a3736527062dcd
https://github.com/django/django/commit/454f2fb93437f98917283336201b4048293f7582
https://github.com/django/django/commit/b7c5feb35a31799de6e582ad6a5a91a9de74e0f9
https://github.com/django/django/commit/beb3f3d55940d9aa7198bf9d424ab74e873aec3d