Lucene search

K
osvGoogleOSV:GHSA-V6RH-HP5X-86RV
HistoryDec 09, 2021 - 7:09 p.m.

Potential bypass of an upstream access control based on URL paths in Django

2021-12-0919:09:37
Google
osv.dev
28
django
http requests
url paths
security issue

EPSS

0.001

Percentile

48.7%

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. This issue has low severity, according to the Django security policy.