Lucene search

K
osvGoogleOSV:USN-4715-2
HistoryFeb 01, 2021 - 3:53 p.m.

python-django vulnerability

2021-02-0115:53:44
Google
osv.dev
7
django
vulnerability
ubuntu 14.04 esm
archive extraction

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

51.0%

USN-4715-1 fixed a vulnerability in Django. This update provides
the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

Wang Baohua discovered that Django incorrectly extracted archive files. A
remote attacker could possibly use this issue to extract files outside of
their expected location.