CVE-2021-3281: Path Traversal
A flaw was found in django where thedjango.utils.archive.extract() function, used by startapp --template and startproject --template, allowed directory-traversal via an archive with absolute paths or relative paths with dot segments.
Other sources
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.
The django.utils.archive.extract() function, used by startapp --template and startproject --template, allowed directory-traversal via an archive with absolute paths or relative paths with dot segments.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/automation-hubto a version that resolves this vulnerability.Fixed in 0:4.2.2-1.el7 - Upgrade
Upgrade
redhat/python3-djangoto a version that resolves this vulnerability.Fixed in 0:2.2.18-1.el7 - Upgrade
Upgrade
redhat/python-bleachto a version that resolves this vulnerability.Fixed in 0:3.3.0-1.el7 - Upgrade
Upgrade
redhat/python-bleach-allowlistto a version that resolves this vulnerability.Fixed in 0:1.0.3-1.el7 - Upgrade
Upgrade
redhat/python-galaxy-importerto a version that resolves this vulnerability.Fixed in 0:0.2.15-1.el7 - Upgrade
Upgrade
redhat/python-galaxy-ngto a version that resolves this vulnerability.Fixed in 0:4.2.2-1.el7 - Upgrade
Upgrade
redhat/python-pulp-ansibleto a version that resolves this vulnerability.Fixed in 1:0.5.6-1.el7 - Upgrade
Upgrade
redhat/automation-hubto a version that resolves this vulnerability.Fixed in 0:4.2.2-1.el8 - Upgrade
Upgrade
redhat/python3-djangoto a version that resolves this vulnerability.Fixed in 0:2.2.18-1.el8 - Upgrade
Upgrade
redhat/python-bleachto a version that resolves this vulnerability.Fixed in 0:3.3.0-1.el8 - Upgrade
Upgrade
redhat/python-bleach-allowlistto a version that resolves this vulnerability.Fixed in 0:1.0.3-1.el8 - Upgrade
Upgrade
redhat/python-galaxy-importerto a version that resolves this vulnerability.Fixed in 0:0.2.15-1.el8 - Upgrade
Upgrade
redhat/python-galaxy-ngto a version that resolves this vulnerability.Fixed in 0:4.2.2-1.el8 - Upgrade
Upgrade
redhat/python-pulp-ansibleto a version that resolves this vulnerability.Fixed in 1:0.5.6-1.el8 - Upgrade
Upgrade
redhat/python-django20to a version that resolves this vulnerability.Fixed in 0:2.0.13-16.el8 - Upgrade
Upgrade
redhat/Djangoto a version that resolves this vulnerability.Fixed in 2.2.18 - Upgrade
Upgrade
redhat/Djangoto a version that resolves this vulnerability.Fixed in 3.0.12 - Upgrade
Upgrade
redhat/Djangoto a version that resolves this vulnerability.Fixed in 3.1.6 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 3.0.12 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 3.1.6 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 2.2.18
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3281.
What is the severity of CVE-2021-3281?
The severity of CVE-2021-3281 is medium with a severity value of 5.3.
What is the affected software?
The affected software is Django versions 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6.
How can this vulnerability be exploited?
This vulnerability can be exploited through a directory traversal attack using an archive with absolute paths or relative paths with dot segments.
Where can I find more information about CVE-2021-3281?
You can find more information about CVE-2021-3281 in the following references: [link1], [link2], [link3].