CVE-2021-45116
Summary
| CVE | CVE-2021-45116 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-05 00:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method call, if passed a suitably crafted key. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180236 Debian Security Update for python-django (CVE-2021-45116)
- 198614 Ubuntu Security Notification for Django Vulnerabilities (USN-5204-1)
- 240566 Red Hat Update for Satellite 6.11 Release (RHSA-2022:5498)
- 282363 Fedora Security Update for python (FEDORA-2022-e7fd530688)
- 296062 Oracle Solaris 11.4 Support Repository Update (SRU) 43.113.3 Missing (CPUJAN2022)
- 502340 Alpine Linux Security Update for py3-django
- 690765 Free Berkeley Software Distribution (FreeBSD) Security Update for django (d3e023fb-6e88-11ec-b948-080027240888)
- 960505 Rocky Linux Security Update for Satellite (RLSA-2022:5498)