Advisories ยป MGASA-2021-0552

Updated python-django packages fix security vulnerability

Publication date: 10 Dec 2021
Modification date: 10 Dec 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-44420

Description

Potential bypass of an upstream access control based on URL paths.
(CVE-2021-44420)
HTTP requests for URLs with trailing newlines could bypass an upstream
access control based on URL paths.
                

References

SRPMS

8/core