Lucene search

K
osvGoogleOSV:GHSA-FVGF-6H6H-3322
HistoryMar 18, 2021 - 8:29 p.m.

Django Directory Traversal via archive.extract

2021-03-1820:29:49
Google
osv.dev
18
django
directory traversal
archive extract
absolute paths
relative paths
security vulnerability

EPSS

0.001

Percentile

51.0%

In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by “startapp --template” and “startproject --template”) allows directory traversal via an archive with absolute paths or relative paths with dot segments.