CVE-2021-3281

Description

In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by startapp --template and startproject --template) allows directory traversal via an archive with absolute paths or relative paths with dot segments.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
36.231

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Netapp Snapcenter -Windows
Vulnerabilities CVE-2021-3281 are fixed in Python-django 2.2.18Windows
Vulnerabilities CVE-2021-3281 are fixed in Python-django 3.0.12Windows
Vulnerabilities CVE-2021-3281 are fixed in Python-django 3.1.6Windows
High-level Python web development framework (USN-4715-1) python-django_1.8.7-1ubuntu5.14_all.debLinux
High-level Python web development framework (USN-4715-1) python3-django_1.8.7-1ubuntu5.14_all.debLinux
High-level Python web development framework (USN-4715-1) python3-django_2.2.12-1ubuntu0.3_all.debLinux
High-level Python web development framework (USN-4715-1) python3-django_2.2.16-1ubuntu0.1_all.debLinux
Vulnerabilities CVE-2021-3281 are fixed in Python-django for linux 2.2.18Linux
Vulnerabilities CVE-2021-3281 are fixed in Python-django for linux 3.0.12Linux
Vulnerabilities CVE-2021-3281 are fixed in Python-django for linux 3.1.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234