Search CVE reports
31 – 40 of 132 results
CVE-2021-44420
Low priorityIn Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
1 affected packages
python-django
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django | — | Fixed | Fixed | Not affected | Not affected |
CVE-2021-35042
Medium priorityDjango 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
1 affected packages
python-django
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django | — | Not affected | Not affected | Not affected | Not affected |
CVE-2021-33571
Medium priorityIn Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access...
1 affected packages
python-django
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django | — | Fixed | Fixed | Not affected | Not affected |
CVE-2021-33203
Low priorityDjango before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files....
1 affected packages
python-django
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django | — | Fixed | Fixed | Fixed | Fixed |
CVE-2021-32052
Medium priorityIn Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in...
1 affected packages
python-django
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django | — | Fixed | Fixed | Fixed | Not affected |
CVE-2021-31542
Medium priorityIn Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
1 affected packages
python-django
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django | — | Fixed | Fixed | Fixed | Fixed |
CVE-2021-28658
Low prioritySome fixes available 12 of 13
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.
1 affected packages
python-django
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2021-21416
Medium prioritydjango-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the...
1 affected packages
python-django-registration
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django-registration | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2020-35681
Medium priorityDjango Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior...
1 affected packages
python-django-channels
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django-channels | Not affected | Not affected | Needs evaluation | Needs evaluation | Not in release |
CVE-2021-23336
Low prioritySome fixes available 12 of 29
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs...
8 affected packages
python-django, python2.7, python3.4, python3.5, python3.6...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-django | Fixed | Fixed | Fixed | Fixed | Not affected |
python2.7 | Not in release | Ignored | Ignored | Ignored | Ignored |
python3.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
python3.5 | Not in release | Not in release | Not in release | Not in release | Ignored |
python3.6 | Not in release | Not in release | Not in release | Ignored | Not in release |
python3.7 | Not in release | Not in release | Not in release | Ignored | Not in release |
python3.8 | Not in release | Not in release | Ignored | Ignored | Not in release |
python3.9 | Not in release | Not in release | Fixed | Not in release | Not in release |