Directory Traversal Affecting python-django package, versions <2:2.2.20-1
Snyk CVSS
Attack Complexity
Low
Threat Intelligence
EPSS
0.76% (81st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIANUNSTABLE-PYTHONDJANGO-1090681
- published 6 Apr 2021
- disclosed 6 Apr 2021
Introduced: 6 Apr 2021
CVE-2021-28658 Open this link in a new tabHow to fix?
Upgrade Debian:unstable
python-django
to version 2:2.2.20-1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream python-django
package and not the python-django
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.