SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-45452

Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

MEDIUM 5.3EPSS 2.41%

Does this matter?

Lower severity and a low EPSS score (2.41%). Track it; it rarely justifies an emergency change on its own.

Description

Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.41% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
djangoproject/django · fedoraproject/fedora
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.