Vulnerabilities > CVE-2021-44420

047910
CVSS 7.3 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
LOW

Summary

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Vulnerable Configurations

Part Description Count
Application
Djangoproject
51
OS
Redhat
1
OS
Debian
2
OS
Canonical
3
OS
Fedoraproject
1