PT-2021-24086 · Django+4 · Django+4

Sjoerd Job Postmus

+1

·

Published

2021-12-07

·

Updated

2025-01-27

·

CVE-2021-44420

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Django versions 2.2 before 2.2.25 Django versions 3.1 before 3.1.14 Django versions 3.2 before 3.2.10
Description: HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. This issue has low severity, according to the Django security policy.
Recommendations: For Django versions 2.2 before 2.2.25, update to version 2.2.25 or later. For Django versions 3.1 before 3.1.14, update to version 3.1.14 or later. For Django versions 3.2 before 3.2.10, update to version 3.2.10 or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3552
ALT-PU-2021-3619
ALT-PU-2021-3622
BIT-DJANGO-2021-44420
CVE-2021-44420
GHSA-V6RH-HP5X-86RV
MGASA-2021-0552
OPENSUSE-SU-2023:0005-1
OPENSUSE-SU-2024:11791-1
OPENSUSE-SU-2025:14702-1
PYSEC-2021-439
RHSA-2022:5498
RHSA-2023:0742
RLSA-2022:5498
USN-5178-1

Affected Products

Alt Linux
Django
Linuxmint
Rocky Linux
Ubuntu