summaryrefslogtreecommitdiffstats
path: root/data/CVE/2021.list
diff options
context:
space:
mode:
authorChris Lamb <lamby@debian.org>2021-12-07 14:55:11 -0800
committerChris Lamb <lamby@debian.org>2021-12-07 14:55:11 -0800
commitf6814ff139feec0ef1ec80536327884449725673 (patch)
tree2e45fb68f35c4cefe38dc9c45ed76e04632181c8 /data/CVE/2021.list
parent27d0cbb366a0883f9cbd0019ca4434eff2091691 (diff)
Triage CVE-2021-44420 in python-django for stretch LTS.
Diffstat (limited to 'data/CVE/2021.list')
-rw-r--r--data/CVE/2021.list1
1 files changed, 1 insertions, 0 deletions
diff --git a/data/CVE/2021.list b/data/CVE/2021.list
index 38e049390f..d9492fb555 100644
--- a/data/CVE/2021.list
+++ b/data/CVE/2021.list
@@ -688,6 +688,7 @@ CVE-2021-44420 [Potential bypass of an upstream access control based on URL path
- python-django 2:3.2.10-1
[bullseye] - python-django <no-dsa> (Minor issue)
[buster] - python-django <no-dsa> (Minor issue)
+ [stretch] - python-django <not-affected> (Vulnerable code not present; path converters added later)
NOTE: https://www.openwall.com/lists/oss-security/2021/12/07/1
NOTE: https://www.djangoproject.com/weblog/2021/dec/07/security-releases/
NOTE: https://github.com/django/django/commit/333c65603032c377e682cdbd7388657a5463a05a (3.2.10)

© 2014-2024 Faster IT GmbH | imprint | privacy policy