CVE Vulnerabilities

CVE-2021-44420

Published: Dec 08, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject 2.2 (including) 2.2.25 (excluding)
Django Djangoproject 3.1 (including) 3.1.14 (excluding)
Django Djangoproject 3.2 (including) 3.2.10 (excluding)

References