Vulnerability Name: | CVE-2021-28658 (CCN-199481) | ||||||||||||||||||||||||
Assigned: | 2021-04-06 | ||||||||||||||||||||||||
Published: | 2021-04-06 | ||||||||||||||||||||||||
Updated: | 2021-06-04 | ||||||||||||||||||||||||
Summary: | In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-22 | ||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-28658 Source: MISC Type: Vendor Advisory https://docs.djangoproject.com/en/3.1/releases/security/ Source: XF Type: UNKNOWN django-cve202128658-dir-traversal(199481) Source: CCN Type: Django GIT Repository [2.2.x] Fixed CVE-2021-28658 -- Fixed potential directory-traversal Source: MISC Type: Mailing List, Third Party Advisory https://groups.google.com/g/django-announce/c/ePr5j-ngdPU Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20210409 [SECURITY] [DLA 2622-1] python-django security update Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-01044b8a59 Source: CCN Type: oss-sec Mailing List, Tue, 6 Apr 2021 09:54:31 +0200 Django: CVE-2021-28658: Potential directory-traversal via uploaded files Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20210528-0001/ Source: CONFIRM Type: Vendor Advisory https://www.djangoproject.com/weblog/2021/apr/06/security-releases/ | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |