An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method call, if passed a suitably crafted key.
References
Link | Resource |
---|---|
https://docs.djangoproject.com/en/4.0/releases/security/ | Patch Vendor Advisory |
https://groups.google.com/forum/#!forum/django-announce | Third Party Advisory |
https://www.djangoproject.com/weblog/2022/jan/04/security-releases/ | Patch Vendor Advisory |
https://security.netapp.com/advisory/ntap-20220121-0005/ | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/ | Mailing List Third Party Advisory |
Information
Published : 2022-01-04 16:15
Updated : 2022-02-10 21:35
NVD link : CVE-2021-45116
Mitre link : CVE-2021-45116
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
djangoproject
- django
fedoraproject
- fedora