• 公告ID (KylinSec-SA-2022-1160)

摘要:

Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by application developers to also show file contents, then not only the existence but also the file contents would have been exposed. In other words, there is directory traversal outside of the template root directories.

安全等级: Low

公告ID: KylinSec-SA-2022-1160

发布日期: 2022年11月18日

关联CVE: CVE-2021-33203  

  • 详细介绍

1. 漏洞描述

   

Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by application developers to also show file contents, then not only the existence but also the file contents would have been exposed. In other words, there is directory traversal outside of the template root directories.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-33203 KY3.4-4A python-django Unaffected
CVE-2021-33203 KY3.4-5A python-django Unaffected
CVE-2021-33203 KY3.5.1 python-django Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-1159 下一篇:KylinSec-SA-2022-1161