VDB

PYSEC-2021-439

PYSEC-2021-439 PUBLISHED

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Affected Products

VendorProductVersions
PyPIdjango2.2, 3.2, 2.2

Timeline

  • Dec 8, 2021 CVE Published
  • Dec 6, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›