Vulnerability Details CVE-2021-31542
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 87.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-31542
-
cpe:2.3:a:djangoproject:django:2.2
-
cpe:2.3:a:djangoproject:django:2.2.1
-
cpe:2.3:a:djangoproject:django:2.2.10
-
cpe:2.3:a:djangoproject:django:2.2.11
-
cpe:2.3:a:djangoproject:django:2.2.13
-
cpe:2.3:a:djangoproject:django:2.2.14
-
cpe:2.3:a:djangoproject:django:2.2.15
-
cpe:2.3:a:djangoproject:django:2.2.16
-
cpe:2.3:a:djangoproject:django:2.2.17
-
cpe:2.3:a:djangoproject:django:2.2.18
-
cpe:2.3:a:djangoproject:django:2.2.19
-
cpe:2.3:a:djangoproject:django:2.2.2
-
cpe:2.3:a:djangoproject:django:2.2.20
-
cpe:2.3:a:djangoproject:django:2.2.3
-
cpe:2.3:a:djangoproject:django:2.2.4
-
cpe:2.3:a:djangoproject:django:2.2.5
-
cpe:2.3:a:djangoproject:django:2.2.6
-
cpe:2.3:a:djangoproject:django:2.2.7
-
cpe:2.3:a:djangoproject:django:2.2.8
-
cpe:2.3:a:djangoproject:django:2.2.9
-
cpe:2.3:a:djangoproject:django:3.1
-
cpe:2.3:a:djangoproject:django:3.1.1
-
cpe:2.3:a:djangoproject:django:3.1.2
-
cpe:2.3:a:djangoproject:django:3.1.3
-
cpe:2.3:a:djangoproject:django:3.1.4
-
cpe:2.3:a:djangoproject:django:3.1.5
-
cpe:2.3:a:djangoproject:django:3.1.6
-
cpe:2.3:a:djangoproject:django:3.1.7
-
cpe:2.3:a:djangoproject:django:3.1.8
-
cpe:2.3:a:djangoproject:django:3.2
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:fedoraproject:fedora:34
-
cpe:2.3:o:fedoraproject:fedora:35