CVE-2021-45452

MEDIUM

Django 2.2-2.2.25, 3.2-3.2.10, 4.0-4.0.0 - Path Traversal via Storage.save

Title source: llm
STIX 2.1

Description

Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

References (5)

Core 5
Core References
Patch, Vendor Advisory x_refsource_misc
https://docs.djangoproject.com/en/4.0/releases/security/
Patch, Vendor Advisory x_refsource_confirm
https://www.djangoproject.com/weblog/2022/jan/04/security-releases/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220121-0005/

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (3)
djangoproject/django 2.2 - 2.2.26
fedoraproject/fedora 35
pypi/Django 2.2 - 2.2.26PyPI
Published Jan 05, 2022
Tracked Since Feb 18, 2026