ISOMAN

CVE

CVE-2021-44420

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Severity
HIGH
CVSS
7.3
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu20.04.6 amd64 desktopunknownsource
Ubuntu20.04.6 amd64 live-serverunknownsource

References

  1. https://docs.djangoproject.com/en/3.2/releases/security/
  2. https://groups.google.com/forum/#%21forum/django-announce
  3. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/
  4. https://security.netapp.com/advisory/ntap-20211229-0006/
  5. https://www.djangoproject.com/weblog/2021/dec/07/security-releases/
  6. https://www.openwall.com/lists/oss-security/2021/12/07/1
  7. https://docs.djangoproject.com/en/3.2/releases/security/
  8. https://groups.google.com/forum/#%21forum/django-announce
  9. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/
  10. https://security.netapp.com/advisory/ntap-20211229-0006/
  11. https://www.djangoproject.com/weblog/2021/dec/07/security-releases/
  12. https://www.openwall.com/lists/oss-security/2021/12/07/1