216.73.216.197

CVE-2024-39330

· Published 10/07/2024 05:15 · Modified 10/07/2024 05:15

Labels: CVE-2024-39330 2024-07-10CVE-2024-39330[email protected]

Essential information

Published
10/07/2024 05:15
Modified
10/07/2024 05:15
Author
Creator
CISA KEV
No
CWE

Description

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicating the file-path validations from the parent class, potentially allow directory traversal via certain inputs during a save() call. (Built-in Storage sub-classes are unaffected.)

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References