Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6rh-hp5x-86rv

Опубликовано: 09 дек. 2021
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.3

Описание

Potential bypass of an upstream access control based on URL paths in Django

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. This issue has low severity, according to the Django security policy.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 2.2a1, < 2.2.25

2.2.25

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 3.0a1, < 3.1.14

3.1.14

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 3.2a1, < 3.2.10

3.2.10

EPSS

Процентиль: 29%
0.00099
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 3 лет назад

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

CVSS3: 5.3
redhat
больше 3 лет назад

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

CVSS3: 7.3
nvd
больше 3 лет назад

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

CVSS3: 7.3
debian
больше 3 лет назад

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, ...

oracle-oval
около 3 лет назад

ELSA-2022-9341: ol-automation-manager security update (IMPORTANT)

EPSS

Процентиль: 29%
0.00099
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-287