PT-2020-21102 · Django · Django-Sendfile2

Published

2020-06-24

·

Updated

2020-06-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions django-sendfile2 versions prior to 0.6.0
Description The issue arises from django-sendfile2 relying on the backend to correctly limit file paths to SENDFILE ROOT, which is not guaranteed for the simple and development backends, and potentially other backends as well. This problem will be fixed in version 0.6.0.
Recommendations For versions prior to 0.6.0, upgrade to version 0.6.0 and ensure SENDFILE ROOT is set in your settings module.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-6R3C-8XF3-GGRR

Affected Products

Django-Sendfile2