CVE-2021-45452
Summary
| CVE | CVE-2021-45452 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-05 00:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179810 Debian Security Update for python-django (CVE-2021-45452)
- 181236 Debian Security Update for python-django (DLA 3191-1)
- 198614 Ubuntu Security Notification for Django Vulnerabilities (USN-5204-1)
- 240566 Red Hat Update for Satellite 6.11 Release (RHSA-2022:5498)
- 282363 Fedora Security Update for python (FEDORA-2022-e7fd530688)
- 296062 Oracle Solaris 11.4 Support Repository Update (SRU) 43.113.3 Missing (CPUJAN2022)
- 502340 Alpine Linux Security Update for py3-django
- 690765 Free Berkeley Software Distribution (FreeBSD) Security Update for django (d3e023fb-6e88-11ec-b948-080027240888)
- 960505 Rocky Linux Security Update for Satellite (RLSA-2022:5498)