Oval Definition:oval:org.opensuse.security:def:202132052
Revision Date:2022-06-30Version:1
Title:CVE-2021-32052
Description:

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-32052
SUSE CVE-2021-32052
Platform(s):openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • python36-Django-3.2.7-2.3 is installed
  • OR python38-Django-3.2.7-2.3 is installed
  • OR python39-Django-3.2.7-2.3 is installed
  • BACK