Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

Django is vulnerable to Denial of Service attack in formset

GHSA-g8xg-jgj6-49r3 · CVE-2013-0306 · PYSEC-2013-17

Published · Modified

Description

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

Ready to move

Start Securing

Free, no credit card | First findings in minutes