CVE-2021-33203 Information
Description
Django before 2.2.24 3.x before 3.1.12 and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally if (and only if) the default admindocs templates have been customized by application developers to also show file contents then not only the existence but also the file contents would have been exposed. In other words there is directory traversal outside of the template root directories.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Reference
https://docs.djangoproject.com/en/3.2/releases/security/ https://www.djangoproject.com/weblog/2021/jun/02/security-releases/ https://groups.google.com/forum/#!forum/django-announce https://security.netapp.com/advisory/ntap-20210727-0004/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
4.9
Share on: