Description
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2540-1 | python-django security update |
Debian DLA |
DLA-3164-1 | python-django security update |
Github GHSA |
GHSA-fvgf-6h6h-3322 | Django Directory Traversal via archive.extract |
Ubuntu USN |
USN-4715-1 | Django vulnerability |
Ubuntu USN |
USN-4715-2 | Django vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T16:53:17.221Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-3281
No data.
Status : Modified
Published: 2021-02-02T07:15:14.020
Modified: 2024-11-21T06:21:12.677
Link: CVE-2021-3281
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA
Ubuntu USN