Fiche vulnérabilité
CVE-2021-44420 : faille élevée djangoproject django (CVSS 7.3)
Description
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
En bref
- Sévérité
- Élevée (CVSS 7.3)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Exploitation active
- Non signalée par la CISA
- Publication
- 8 déc. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- djangoproject django
- redhat satellite
- debian debian linux
- canonical ubuntu linux
- fedoraproject fedora
Références
- Fiche CVE-2021-44420 sur le NVD (NIST)
- docs.djangoproject.com/en/3.2/releases/security/
- groups.google.com/forum/
- lists.fedoraproject.org/archives/list/package…
- security.netapp.com/advisory/ntap-20211229-0006/
- djangoproject.com/weblog/2021/dec/07/security-releases/
- openwall.com/lists/oss-security/2021/12/07/1