QID 980642
QID 980642: Python (pip) Security Update for django (GHSA-fvgf-6h6h-3322)
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fvgf-6h6h-3322 for updates pertaining to this vulnerability.
Vendor References
- GHSA-fvgf-6h6h-3322 -
github.com/advisories/GHSA-fvgf-6h6h-3322
CVEs related to QID 980642
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fvgf-6h6h-3322 | django |
|