CVE-2021-45116
HIGHDjango 2.2-2.2.25, 3.2-3.2.10, 4.0-4.0.0 - Information Disclosure via dictsort Template Filter
Title source: llmDescription
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method call, if passed a suitably crafted key.
References (5)
Core 5
Core References
Mailing List x_refsource_misc
https://groups.google.com/forum/#%21forum/django-announce
Patch, Vendor Advisory x_refsource_misc
https://docs.djangoproject.com/en/4.0/releases/security/
Patch, Vendor Advisory x_refsource_confirm
https://www.djangoproject.com/weblog/2022/jan/04/security-releases/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220121-0005/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/
Scores
CVSS v3
7.5
EPSS
0.0036
EPSS Percentile
58.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (3)
djangoproject/django
2.2 - 2.2.26
fedoraproject/fedora
35
pypi/Django
2.2 - 2.2.26PyPI
Published
Jan 05, 2022
Tracked Since
Feb 18, 2026