← Back

CVE-2021-45452

nvd nist
Published: Jan 5, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

Affected (4)

1 product
Django
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
From 2.2 to 2.2.26
From 3.2 to 3.2.11
From 4.0 to 4.0.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 35

Timeline

No history available yet.