CVE-2021-45116

HIGH

Django 2.2-2.2.25, 3.2-3.2.10, 4.0-4.0.0 - Information Disclosure via dictsort Template Filter

Title source: llm
STIX 2.1

Description

An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method call, if passed a suitably crafted key.

References (5)

Core 5
Core References
Patch, Vendor Advisory x_refsource_misc
https://docs.djangoproject.com/en/4.0/releases/security/
Patch, Vendor Advisory x_refsource_confirm
https://www.djangoproject.com/weblog/2022/jan/04/security-releases/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220121-0005/

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 58.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (3)
djangoproject/django 2.2 - 2.2.26
fedoraproject/fedora 35
pypi/Django 2.2 - 2.2.26PyPI
Published Jan 05, 2022
Tracked Since Feb 18, 2026