CVE-2021-44420

Source
https://cve.org/CVERecord?id=CVE-2021-44420
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44420.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-44420
Aliases
Downstream
Related
Published
2021-12-08T00:15:07.757Z
Modified
2026-02-05T04:28:54.453082Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

References

Affected packages

Git / github.com/django/django

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44420.json"