In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
| Software | From | Fixed in |
|---|---|---|
| djangoproject / django | 2.2 | 2.2.25 |
| djangoproject / django | 3.1 | 3.1.14 |
| djangoproject / django | 3.2 | 3.2.10 |
| redhat / satellite | 6.0 | 6.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |
| canonical / ubuntu_linux | 20.04 | 20.04.x |
| canonical / ubuntu_linux | 21.04 | 21.04.x |
| canonical / ubuntu_linux | 21.10 | 21.10.x |
| fedoraproject / fedora | 35 | 35.x |
Django
|
- | 2.2.25 |
Django
|
3.0 | 3.1.14 |
Django
|
3.2 | 3.2.10 |