CVE-2021-33203
Summary
| CVE | CVE-2021-33203 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-08 18:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by application developers to also show file contents, then not only the existence but also the file contents would have been exposed. In other words, there is directory traversal outside of the template root directories. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159768 Oracle Enterprise Linux Security Update for ol-automation-manager (ELSA-2022-9341)
- 178658 Debian Security Update for python-django (DLA 2676-1)
- 180212 Debian Security Update for python-django (CVE-2021-33203)
- 198394 Ubuntu Security Notification for Django vulnerabilities (USN-4975-1)
- 239639 Red Hat Update for Red Hat OpenStack Platform 16.2 (python-django20) (RHSA-2021:3490)
- 239895 Red Hat Update for Satellite 6.10 (RHSA-2021:4702)
- 239944 Red Hat Update for OpenStack Platform 16.1 (RHSA-2021:5070)
- 239947 Red Hat Update for OpenStack Platform 16.1
- 239950 Red Hat Update for OpenStack Platform 16.1
- 239953 Red Hat Update for OpenStack Platform 16.1
- 239955 Red Hat Update for OpenStack Platform 16.1
- 239959 Red Hat Update for OpenStack Platform 16.1
- 282363 Fedora Security Update for python (FEDORA-2022-e7fd530688)
- 296053 Oracle Solaris 11.4 Support Repository Update (SRU) 35.94.4 Missing (CPUJUL2021)
- 501675 Alpine Linux Security Update for py3-django
- 505299 Alpine Linux Security Update for py3-django
- 6000500 Debian Security Update for python-django (DLA 3744-1)
- 980874 Python (pip) Security Update for django (GHSA-68w8-qjq3-2gfm)