FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Django -- multiple vulnerabilities

Affected packages
py310-django32 < 3.2.19
py311-django32 < 3.2.19
py37-django32 < 3.2.19
py38-django32 < 3.2.19
py39-django32 < 3.2.19
py310-django41 < 4.1.9
py311-django41 < 4.1.9
py38-django41 < 4.1.9
py39-django41 < 4.1.9
py310-django42 < 4.2.1
py311-django42 < 4.2.1
py38-django42 < 4.2.1
py39-django42 < 4.2.1

Details

VuXML ID d55e1b4d-eadc-11ed-9cc0-080027de9982
Discovery 2023-05-01
Entry 2023-05-05

Django reports:

CVE-2023-31047: Potential bypass of validation when uploading multiple files using one form field.

References

CVE Name CVE-2023-31047
URL https://www.djangoproject.com/weblog/2023/may/03/security-releases/