MGASA-2022-0011

    Dashboard / Vulnerabilities / MGASA-2022-0011

    MGASA-2022-0011

    Published: 11 Jan 2022Last Modified: 16 Apr 2026

    Summary: Updated python-django packages fix security vulnerability

    Details: UserAttributeSimilarityValidator incurred significant overhead evaluating submitted password that were artificially large in relative to the comparison values. On the assumption that access to user registration was unrestricted this provided a potential vector for a denial-of-service attack. (CVE-2021-45115) Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure or unintended method calls, if passed a suitably crafted key. (CVE-2021-45116) Storage.save() allowed directory-traversal if directly passed suitably crafted file names. (CVE-2021-45452)

    Affected packages

    Package

    Name: python-django

    Purl: pkg:rpm/mageia/python-django?arch=source&distro=mageia-8

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.1.14-1.1.mga8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    MGASA-2022-0011 | CVE-DB