Lack of data validation - Path Traversal In django
Description
Directory traversal in Django Directory traversal vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 on Windows might allow remote attackers to read or execute files via a / (slash) character in a key in a session cookie, related to session replays.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 1.1.4, 1.2.5 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6. 7.