In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3415-1 | python-django security update |
Debian DSA |
DSA-5465-1 | python-django security update |
EUVD |
EUVD-2023-0071 | In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's \"Uploading multiple files\" documentation suggested otherwise. |
Github GHSA |
GHSA-r3xc-prgr-mg9p | Django bypasses validation when using one form field to upload multiple files |
Ubuntu USN |
USN-6054-1 | Django vulnerability |
Ubuntu USN |
USN-6054-2 | Django vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jan 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-29T15:51:24.644Z
Reserved: 2023-04-24T00:00:00.000Z
Link: CVE-2023-31047
Updated: 2024-08-02T14:45:25.559Z
Status : Modified
Published: 2023-05-07T02:15:08.917
Modified: 2025-01-29T16:15:42.863
Link: CVE-2023-31047
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN