5.3
CVSSv3

CVE-2021-28658

Published: 06/04/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Django 2.2 prior to 2.2.20, 3.0 prior to 3.0.14, and 3.1 prior to 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django

debian debian linux 9.0

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #986447 python-django: CVE-2021-28658 Package: python-django; Maintainer for python-django is Debian Python Team <team+python@trackerdebianorg>; Source for python-django is src:python-django (PTS, buildd, popcon) Reported by: "Chris Lamb" <lamby@debianorg> Date: Tue, 6 Apr 2021 08:42:02 U ...
A security issue was discovered in Django before versions 318, 3014 and 2220 MultiPartParser allowed directory-traversal via uploaded files with suitably crafted file names Built-in upload handlers were not affected by this vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Django: CVE-2021-28658: Potential directory-traversal via uploaded files <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...