Lucene search

K
osvGoogleOSV:GHSA-RXJP-MFM9-W4WR
HistoryJun 04, 2021 - 9:15 p.m.

Path Traversal in Django

2021-06-0421:15:56
Google
osv.dev
19
django
path traversal
multipartparser
uploadedfile
fieldfile
directory traversal

EPSS

0.002

Percentile

59.7%

In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

References