CVE-2021-32052
Summary
| CVE | CVE-2021-32052 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-06 16:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Redirecting to Google Groups |
|
groups.google.com |
|
| oss-security - Django: CVE-2021-32052: Header injection possibility since
URLValidator accepted newlines in input on Python 3.9.5+ |
MISC |
www.openwall.com |
|
| Redirecting to Google Groups |
MISC |
groups.google.com |
|
| Archive of security issues | Django documentation | Django |
MISC |
docs.djangoproject.com |
|
| Django security releases issued: 3.2.2, 3.1.10, and 2.2.22 | Weblog | Django |
MISC |
www.djangoproject.com |
|
| [SECURITY] Fedora 34 Update: python-django-3.1.9-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: python-django-3.1.9-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE-2021-32052 Django Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179879 Debian Security Update for python-django (CVE-2021-32052)
- 198394 Ubuntu Security Notification for Django vulnerabilities (USN-4975-1)
- 198736 Ubuntu Security Notification for Django Vulnerabilities (USN-5373-1)
- 281191 Fedora Security Update for python (FEDORA-2021-01044b8a59)
- 296053 Oracle Solaris 11.4 Support Repository Update (SRU) 35.94.4 Missing (CPUJUL2021)
- 982278 Python (pip) Security Update for Django (GHSA-qm57-vhq3-3fwf)