Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 8: MGASA-2021-0552 Critical: Python-Django Access Control Bypass

mageia
Calendar Grey December 10, 2021
Dist Mageia Esm H88
The recent updates to the python-django packages address possible security vulnerabilities, which could enable unauthorized access through specific URL endpoints.
Potential bypass of an upstream access control based on URL paths

Summary

Potential bypass of an upstream access control based on URL paths. (CVE-2021-44420) HTTP requests for URLs with trailing newlines could bypass an upstream access control based on URL paths.

References

- https://bugs.mageia.org/show_bug.cgi?id=29737

- https://www.djangoproject.com/weblog/2021/dec/07/security-releases/

- https://ubuntu.com/security/notices/USN-5178-1

- https://www.cve.org/CVERecord?id=CVE-2021-44420

Resolution

SRPMS

- 8/core/python-django-3.1.14-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0552.html
Type: security
CVE: CVE-2021-44420

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here