← Back

CVE-2021-44420

nvd nist
Published: Dec 8, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Affected (10)

Products: Djangoproject: Django · Redhat: Satellite · Debian: Debian Linux · +2 more
Show all products
1 product
Django
1 product
Satellite
1 product
Debian Linux
1 product
Ubuntu Linux
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
From 2.2 to 2.2.25
From 3.1 to 3.1.14
From 3.2 to 3.2.10
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 20.04
Version 21.04
Version 21.10
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 35

References (12)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory

Timeline

No history available yet.