ZeroHour

CVE-2021-45452

CVSS 3.1
5.3 medium
EPSS
2%p83
Published
()
Modified
Description

Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

Vendors
djangoprojectfedoraproject
Products
django, fedora
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.