← Back

CVE-2021-33203

nvd nist
Published: Jun 8, 2021Modified: Jun 17, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by application developers to also show file contents, then not only the existence but also the file contents would have been exposed. In other words, there is directory traversal outside of the template root directories.

Affected (4)

1 product
Django
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Before 2.2.24
From 3.0.0 to 3.1.12
From 3.2.0 to 3.2.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 35

Timeline

No history available yet.