QID 982377
QID 982377: Python (pip) Security Update for Django (GHSA-xgxc-v2qg-chmh)
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xgxc-v2qg-chmh for updates pertaining to this vulnerability.
Vendor References
- GHSA-xgxc-v2qg-chmh -
github.com/advisories/GHSA-xgxc-v2qg-chmh
CVEs related to QID 982377
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xgxc-v2qg-chmh | Django |
|