VDB
PYSEC-2021-7
PYSEC-2021-7
PUBLISHED
CVSS 8.699999809265137 HIGH
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | django | 2.2, 3.1, 3.2 |
Timeline
- May 5, 2021 CVE Published
- Dec 6, 2023 CVE Updated
References
- https://www.djangoproject.com/weblog/2021/may/04/security-releases/ article
- https://docs.djangoproject.com/en/3.2/releases/security/ url
- http://www.openwall.com/lists/oss-security/2021/05/04/3 url
- https://groups.google.com/forum/#!forum/django-announce url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE/ url
- https://github.com/advisories/GHSA-rxjp-mfm9-w4wr advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00005.html advisory