Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2021-31542 - CERT CVE
CVE-2021-31542
ID
CVE-2021-31542
Sažetak
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
Reference
http://www.openwall.com/lists/oss-security/2021/05/04/3
https://docs.djangoproject.com/en/3.2/releases/security/
https://github.com/django/django/commit/04ac1624bdc2fa737188401757cf95ced122d26d
https://github.com/django/django/commit/25d84d64122c15050a0ee739e859f22ddab5ac48
https://github.com/django/django/commit/c98f446c188596d4ba6de71d1b77b4a6c5c2a007
https://groups.google.com/forum/#%21forum/django-announce
https://lists.debian.org/debian-lts-announce/2021/05/msg00005.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE/
https://security.netapp.com/advisory/ntap-20210618-0001/
https://www.djangoproject.com/weblog/2021/may/04/security-releases/
CVSS
Base:
5.0
Impact:
2.9
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
PARTIAL
NONE
NONE
CVSS vektor
AV:N/AC:L/Au:N/C:P/I:N/A:N
Zadnje važnije ažuriranje
07-12-2023 - 22:15
Objavljeno
05-05-2021 - 15:15