UBUNTU-CVE-2021-33571
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-33571
UBUNTU-CVE-2021-33571
Summary:
Details: In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .
References: https://ubuntu.com/security/CVE-2021-33571, https://www.djangoproject.com/weblog/2021/jun/02/security-releases/, https://ubuntu.com/security/notices/USN-4975-1, https://www.cve.org/CVERecord?id=CVE-2021-33571
Affected packages
Package
Name: python-django
Purl: pkg:deb/ubuntu/python-django@2:2.2.12-1ubuntu0.7?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
