PT-2021-24086 · Django+4 · Django+4
Sjoerd Job Postmus
+1
·
Published
2021-12-07
·
Updated
2025-01-27
·
CVE-2021-44420
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Django versions 2.2 before 2.2.25
Django versions 3.1 before 3.1.14
Django versions 3.2 before 3.2.10
Description:
HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. This issue has low severity, according to the Django security policy.
Recommendations:
For Django versions 2.2 before 2.2.25, update to version 2.2.25 or later.
For Django versions 3.1 before 3.1.14, update to version 3.1.14 or later.
For Django versions 3.2 before 3.2.10, update to version 3.2.10 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Django
Linuxmint
Rocky Linux
Ubuntu