CVE-2021-44420 The advisory has been revoked - it doesn't affect any version of package python-django Open this link in a new tab


    Threat Intelligence

    EPSS 0.11% (44th percentile)
Expand this section
NVD
7.3 high
Expand this section
Red Hat
5.3 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIAN10-PYTHONDJANGO-2311799
  • published 7 Dec 2021
  • disclosed 8 Dec 2021

Amendment

The Debian security team deemed this advisory irrelevant for Debian:10.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python-django package and not the python-django package as distributed by Debian.

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.