CVE Vulnerabilities

CVE-2021-44420

Published: Dec 08, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Affected Software

NameVendorStart VersionEnd Version
DjangoDjangoproject2.2 (including)2.2.25 (excluding)
DjangoDjangoproject3.1 (including)3.1.14 (excluding)
DjangoDjangoproject3.2 (including)3.2.10 (excluding)
Red Hat Satellite 6.11 for RHEL 8RedHatpython-django-0:3.2.13-1.el8pc*
Red Hat Satellite 6.11 for RHEL 8RedHatpython-django-0:3.2.13-1.el8pc*
RHUI 4 for RHEL 8RedHatpython-django-0:3.2.16-1.0.1.el8ui*
Python-djangoUbuntudevel*
Python-djangoUbuntuesm-infra/focal*
Python-djangoUbuntufocal*
Python-djangoUbuntuhirsute*
Python-djangoUbuntuimpish*
Python-djangoUbuntujammy*
Python-djangoUbuntuupstream*

References