CVE-2021-31542

Related Vulnerabilities: CVE-2021-31542  

A flaw was found in django. ``MultiPartParser``, ``UploadedFile``, and ``FieldFile`` allowed directory-traversal via uploaded files with suitably crafted file names.

Description

A flaw was found in django. ``MultiPartParser``, ``UploadedFile``, and ``FieldFile`` allowed directory-traversal via uploaded files with suitably crafted file names.

Additional Information

  • Bugzilla 1954294: CVE-2021-31542 django: Potential directory-traversal via uploaded files
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • FAQ: Frequently asked questions about CVE-2021-31542