Safety vulnerability ID: 40163
The information on this page was manually curated by our Cybersecurity Intelligence Team.
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.
Latest version: 5.1.3
A high-level Python web framework that encourages rapid development and clean, pragmatic design.
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability. See CVE-2021-28658.
CONFIRM:https://www.djangoproject.com/weblog/2021/apr/06/security-releases/: https://www.djangoproject.com/weblog/2021/apr/06/security-releases/
MISC:https://docs.djangoproject.com/en/3.1/releases/security/: https://docs.djangoproject.com/en/3.1/releases/security/
MISC:https://groups.google.com/g/django-announce/c/ePr5j-ngdPU: https://groups.google.com/g/django-announce/c/ePr5j-ngdPU
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application