Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-33571

Опубликовано: 08 июн. 2021
Источник: debian
EPSS Низкий

Описание

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed2:2.2.24-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2021/06/02/1

  • https://github.com/django/django/commit/e1d787f1b36d13b95187f8f425425ae1b98da188 (main)

  • https://github.com/django/django/commit/f27c38ab5d90f68c9dd60cabef248a570c0be8fc (2.2.24)

EPSS

Процентиль: 2%
0.00014
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .

CVSS3: 7.5
redhat
около 4 лет назад

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .

CVSS3: 7.5
nvd
около 4 лет назад

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .

CVSS3: 7.5
github
около 4 лет назад

Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks

CVSS3: 7.5
fstec
около 4 лет назад

Уязвимость функций URLValidator, validate_ipv4_address, validate_ipv46_address программной платформы для веб-приложений Django, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 2%
0.00014
Низкий