CVE-2022-22818
Summary
| CVE | CVE-2022-22818 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-03 02:15:00 UTC |
| Updated | 2023-11-07 03:43:00 UTC |
| Description | The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179049 Debian Security Update for python-django (DLA 2906-1)
- 181137 Debian Security Update for python-django (DSA 5254-1)
- 181236 Debian Security Update for python-django (DLA 3191-1)
- 184928 Debian Security Update for python-django (CVE-2022-22818)
- 198652 Ubuntu Security Notification for Django Vulnerabilities (USN-5269-1)
- 240566 Red Hat Update for Satellite 6.11 Release (RHSA-2022:5498)
- 240925 Red Hat Update for Satellite 6.12 (RHSA-2022:8506)
- 240972 Red Hat Update for OpenStack Platform 16.1.9 (RHSA-2022:8872)
- 240979 Red Hat Update for OpenStack Platform 16.2.4 (RHSA-2022:8853)
- 282363 Fedora Security Update for python (FEDORA-2022-e7fd530688)
- 502340 Alpine Linux Security Update for py3-django
- 960485 Rocky Linux Security Update for Satellite (RLSA-2022:8506)
- 960505 Rocky Linux Security Update for Satellite (RLSA-2022:5498)