VulnerabilityModified
CVE-2021-28658
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names.
MEDIUM 5.3EPSS 3.86%
Does this matter?
Lower severity and a low EPSS score (3.86%). Track it; it rarely justifies an emergency change on its own.
Description
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 3.86% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- djangoproject/django · debian/debian linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- https://docs.djangoproject.com/en/3.1/releases/security/Vendor Advisory
- https://groups.google.com/g/django-announce/c/ePr5j-ngdPUMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00008.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE/
- https://security.netapp.com/advisory/ntap-20210528-0001/Third Party Advisory
- https://www.djangoproject.com/weblog/2021/apr/06/security-releases/Vendor Advisory
- https://docs.djangoproject.com/en/3.1/releases/security/Vendor Advisory
- https://groups.google.com/g/django-announce/c/ePr5j-ngdPUMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00008.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE/
- https://security.netapp.com/advisory/ntap-20210528-0001/Third Party Advisory
- https://www.djangoproject.com/weblog/2021/apr/06/security-releases/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.