5.3
CVSSv3

CVE-2021-45452

Published: 05/01/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Storage.save in Django 2.2 prior to 2.2.26, 3.2 prior to 3.2.11, and 4.0 prior to 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django

fedoraproject fedora 35

Vendor Advisories

Synopsis Moderate: Satellite 611 Release Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Satellite 611 Description Red Hat Satellite is a systems management tool for Linux-basedin ...
Debian Bug report logs - #1003113 python-django: CVE-2021-45115, CVE-2021-45116 & CVE-2021-45452 Package: python-django; Maintainer for python-django is Debian Python Team <team+python@trackerdebianorg>; Source for python-django is src:python-django (PTS, buildd, popcon) Reported by: "Chris Lamb" <lamby@debianorg&g ...

Github Repositories

Django storage backend for Thumbor

django-thumborstorage A Django custom storage for Thumbor Provides 2 custom storages classes: ThumborStorage and ThumborMigrationStorage Use ThumborMigrationStorage on an Imagefield that started with a classic FileSystemStorage you want to upgrade to Thumbor without migrating your old media That way, Django continues to serve them from the file system until the image is c