CVE-2021-44420

Source
https://cve.org/CVERecord?id=CVE-2021-44420
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44420.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-44420
Aliases
Downstream
Related
Published
2021-12-08T00:15:07.757Z
Modified
2026-05-28T04:07:08.286480543Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "20.04"
                },
                {
                    "last_affected": "21.04"
                },
                {
                    "last_affected": "21.10"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "canonical:ubuntu_linux",
            "cpes": [
                "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*",
                "cpe:2.3:o:canonical:ubuntu_linux:21.04:*:*:*:*:*:*:*",
                "cpe:2.3:o:canonical:ubuntu_linux:21.10:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "last_affected": "10.0"
                },
                {
                    "last_affected": "11.0"
                }
            ],
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "debian:debian_linux"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "35"
                }
            ],
            "cpes": [
                "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "fedoraproject:fedora"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "6.0"
                }
            ],
            "vendor_product": "redhat:satellite",
            "cpes": [
                "cpe:2.3:o:redhat:satellite:6.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/django/django

Affected ranges

Type
GIT
Repo
https://github.com/django/django
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.2"
        },
        {
            "fixed": "2.2.25"
        },
        {
            "introduced": "3.1"
        },
        {
            "fixed": "3.1.14"
        },
        {
            "introduced": "3.2"
        },
        {
            "fixed": "3.2.10"
        }
    ],
    "cpe": "cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44420.json"