GHSA-pcjh-6r5h-r92r

    Dashboard / Vulnerabilities / GHSA-pcjh-6r5h-r92r

    GHSA-pcjh-6r5h-r92r

    Published: 11 Aug 2022Last Modified: 3 Dec 2024

    Summary: django-sendfile2 before 0.7.0 contains reflected file download vulnerability

    Details: Similar to CVE-2022-36359 for Django, django-sendfile2 did not protect against a reflected file download attack in version 0.6.1 and earlier. If the file name used by django-sendfile2 was derived from user input, then it would be possible to perform a such an attack. A new version of django-sendfile2 will be released. Either download django-sendfile2 0.7.0 as a workaround or sanitize user input yourself, using Django's patch as a template: https://github.com/django/django/commit/bd062445cffd3f6cc6dcd20d13e2abed818fa173

    Affected packages

    Package

    Name: django-sendfile2

    Purl: pkg:pypi/django-sendfile2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.7.0

    Affected versions

    0.4.0
    0.4.1
    0.4.2
    0.4.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-pcjh-6r5h-r92r | CVE-DB