Description
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
Published: 2021-12-07
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-0062 In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
Github GHSA Github GHSA GHSA-v6rh-hp5x-86rv Potential bypass of an upstream access control based on URL paths in Django
Ubuntu USN Ubuntu USN USN-5178-1 Django vulnerability
History

No history.

Subscriptions

Canonical Ubuntu Linux
Debian Debian Linux
Djangoproject Django
Fedoraproject Fedora
Redhat Rhui Satellite Satellite Capsule
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T04:17:25.193Z

Reserved: 2021-11-29T00:00:00.000Z

Link: CVE-2021-44420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-08T00:15:07.757

Modified: 2024-11-21T06:30:56.037

Link: CVE-2021-44420

cve-icon Redhat

Severity : Low

Publid Date: 2021-12-07T08:00:00Z

Links: CVE-2021-44420 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses