Fiche vulnérabilité
CVE-2021-31542 : faille élevée djangoproject django (CVSS 7.5)
Description
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 5 mai 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- djangoproject django
- debian debian linux
- fedoraproject fedora
Références
- Fiche CVE-2021-31542 sur le NVD (NIST)
- openwall.com/lists/oss-security/2021/05/04/3
- docs.djangoproject.com/en/3.2/releases/security/
- github.com/django/django/commit/04ac1624bdc2fa73718840175…
- github.com/django/django/commit/25d84d64122c15050a0ee739e…
- github.com/django/django/commit/c98f446c188596d4ba6de71d1…
- groups.google.com/forum/
- lists.debian.org/debian-lts-announce/2021/05/msg00005.html
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- security.netapp.com/advisory/ntap-20210618-0001/
- djangoproject.com/weblog/2021/may/04/security-releases/