Vulnerability Description
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Djangoproject | Django | >= 2.2, < 2.2.25 |
| Redhat | Satellite | 6.0 |
| Debian | Debian Linux | 10.0 |
| Canonical | Ubuntu Linux | 20.04 |
| Fedoraproject | Fedora | 35 |
References
- https://docs.djangoproject.com/en/3.2/releases/security/PatchVendor Advisory
- https://groups.google.com/forum/#%21forum/django-announce
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20211229-0006/Third Party Advisory
- https://www.djangoproject.com/weblog/2021/dec/07/security-releases/PatchVendor Advisory
- https://www.openwall.com/lists/oss-security/2021/12/07/1Mailing ListPatchThird Party Advisory
- https://docs.djangoproject.com/en/3.2/releases/security/PatchVendor Advisory
- https://groups.google.com/forum/#%21forum/django-announce
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20211229-0006/Third Party Advisory
- https://www.djangoproject.com/weblog/2021/dec/07/security-releases/PatchVendor Advisory
- https://www.openwall.com/lists/oss-security/2021/12/07/1Mailing ListPatchThird Party Advisory
FAQ
What is CVE-2021-44420?
CVE-2021-44420 is a vulnerability with a CVSS score of 7.3 (HIGH). In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
How severe is CVE-2021-44420?
CVE-2021-44420 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44420?
Check the references section above for vendor advisories and patch information. Affected products include: Djangoproject Django, Redhat Satellite, Debian Debian Linux, Canonical Ubuntu Linux, Fedoraproject Fedora.