CVE-2021-3281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
02/02/2021
Last modified:
07/11/2023

Description

In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 2.2 (including) 2.2.18 (excluding)
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 3.0 (including) 3.0.12 (excluding)
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 3.1 (including) 3.1.6 (excluding)
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*