CVE-2021-44420 PUBLISHED

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

EPSS 0.12% · 30.9th percentile

Risk Scores

EPSS Score
0.12%
30.9th percentile

Affected Products

VendorProductVersions
Bitnamidjango3.2.0, 3.2.0, 2.2.0
Bitnamidjango3.1.0, 3.2.0, 2.2.0

Timeline

References

Open in Interactive Console →