Django database denial-of-service with ModelMultipleChoiceField
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2024
Package
Affected versions
>= 1.6, < 1.6.10
>= 1.7, < 1.7.3
Patched versions
1.6.10
1.7.3
Description
Published by the National Vulnerability Database
Jan 16, 2015
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 29, 2024
Last updated
Sep 18, 2024
ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
References