CVE-2021-31542 - Debian Debian Linux, Djangoproject Django and Fedoraproject Fedora

Critical 7.5

In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

Affected software

Debian Debian Linux

Djangoproject Django

Fedoraproject Fedora

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.