CVE-2022-36359
Debian Security Advisory 5254-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.
Se ha detectado un problema en la clase HTTP FileResponse en Django versiones 3.2 anteriores a 3.2.15 y 4.0 anteriores a 4.0.7. Una aplicación es vulnerable a un ataque de descarga de archivos reflejada (RFD) que establece el encabezado Content-Disposition de un FileResponse cuando el nombre del archivo es derivado de la entrada proporcionada por el usuario
An update that fixes one vulnerability is now available. This update for python-Django fixes the following issues. Fixed potential reflected file download vulnerability in FileResponse Backport fix and tests from uptream branch 3.2.X.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-21 CVE Reserved
- 2022-08-03 CVE Published
- 2025-02-13 CVE Updated
- 2025-05-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-494: Download of Code Without Integrity Check
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://groups.google.com/g/django-announce/c/8cz--gvaJr4 | Release Notes | |
https://security.netapp.com/advisory/ntap-20220915-0008 | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2022/08/03/1 | 2023-11-07 | |
https://docs.djangoproject.com/en/4.0/releases/security | 2023-11-07 | |
https://www.djangoproject.com/weblog/2022/aug/03/security-releases | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | >= 3.2 < 3.2.15 Search vendor "Djangoproject" for product "Django" and version " >= 3.2 < 3.2.15" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | >= 4.0 < 4.0.7 Search vendor "Djangoproject" for product "Django" and version " >= 4.0 < 4.0.7" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
|