CVE-2021-45452

MEDIUM5.3EPSS 0.24%

python-django - security update

Published: 1/12/2022Modified: 4/3/2025
Also known as:GHSA-jrh2-hc4r-7jwxBIT-django-2021-45452PYSEC-2022-3

Description

Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (18)