CVE Vulnerabilities

CVE-2021-44420

Published: Dec 08, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
LOW

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject 2.2 (including) 2.2.25 (excluding)
Django Djangoproject 3.1 (including) 3.1.14 (excluding)
Django Djangoproject 3.2 (including) 3.2.10 (excluding)
Red Hat Satellite 6.11 for RHEL 8 RedHat python-django-0:3.2.13-1.el8pc *
Red Hat Satellite 6.11 for RHEL 8 RedHat python-django-0:3.2.13-1.el8pc *
RHUI 4 for RHEL 8 RedHat python-django-0:3.2.16-1.0.1.el8ui *
Python-django Ubuntu devel *
Python-django Ubuntu focal *
Python-django Ubuntu hirsute *
Python-django Ubuntu impish *
Python-django Ubuntu jammy *
Python-django Ubuntu upstream *

References