HTTP: Django Multipartparser.py Parse Denial of Service

This signature detects attempts to exploit a known vulnerability against Django Multipartparser. A successful attack can result in a denial-of-service condition.

Extended Description

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

Affected Products

Debian debian_linux

Short Name
HTTP:DOS:DJANGO-MULTIPRT-PARSE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2023-24580 Denial Django Multipartparser.py Parse Service of
Release Date
03/06/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Djangoproject

Debian

Found a potential security threat?