CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CVE-2021-44420 — HIGH severity vulnerability | Release Alert
CVE-2021-44420
7.3
HIGHCVSS v3
Published
December 8, 2021
CVSS v2
7.5 HIGH
Affected
9 projects
Assigned by
MITRE
Severity scale
010
Description
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.