ZeroHour

CVE-2021-44420

CVSS 3.1
7.3 high
EPSS
2%p82
Published
()
Modified
Description

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Vendors
djangoprojectredhatdebiancanonicalfedoraproject
Products
django, satellite, debian linux, ubuntu linux, fedora
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.