Search CVE reports


Toggle filters

41 – 50 of 139 results


CVE-2021-33203

Low priority
Fixed

Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files....

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed
Show less packages

CVE-2021-3281

Medium priority
Fixed

In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed
Show less packages

CVE-2021-32052

Medium priority
Fixed

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed
Show less packages

CVE-2021-31542

Medium priority
Fixed

In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed
Show less packages

CVE-2021-28658

Low priority

Some fixes available 13 of 14

In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-23336

Low priority

Some fixes available 12 of 29

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs...

8 affected packages

python-django, python2.7, python3.4, python3.5, python3.6...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed Fixed
python2.7 Not in release Ignored Ignored Ignored
python3.4 Not in release Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Ignored
python3.7 Not in release Not in release Not in release Ignored
python3.8 Not in release Not in release Ignored Ignored
python3.9 Not in release Not in release Fixed Not in release
Show all 8 packages Show less packages

CVE-2021-21416

Medium priority
Needs evaluation

django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the...

1 affected package

python-django-registration

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django-registration Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-9402

Medium priority
Fixed

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed
Show less packages

CVE-2020-7471

Medium priority
Fixed

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed
Show less packages

CVE-2020-35681

Medium priority
Needs evaluation

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior...

1 affected package

python-django-channels

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django-channels Not affected Not affected Needs evaluation Needs evaluation
Show less packages