views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when serving protected media.
{
"severity": "MODERATE",
"nvd_published_at": "2023-10-22T19:15:08Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-22"
],
"github_reviewed_at": "2023-10-24T01:45:47Z"
}