mirror of
https://github.com/django/django.git
synced 2025-07-24 05:36:15 +00:00
[3.1.x] Fixed CVE-2021-33571 -- Prevented leading zeros in IPv4 addresses.
validate_ipv4_address() was affected only on Python < 3.9.5, see [1]. URLValidator() uses a regular expressions and it was affected on all Python versions. [1] https://bugs.python.org/issue36384
This commit is contained in:
parent
20c67a0693
commit
203d4ab9eb
6 changed files with 73 additions and 1 deletions
|
@ -17,3 +17,16 @@ the existence but also the file contents would have been exposed.
|
|||
|
||||
As a mitigation, path sanitation is now applied and only files within the
|
||||
template root directories can be loaded.
|
||||
|
||||
CVE-2021-33571: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses
|
||||
===========================================================================================================================
|
||||
|
||||
:class:`~django.core.validators.URLValidator`,
|
||||
:func:`~django.core.validators.validate_ipv4_address`, and
|
||||
:func:`~django.core.validators.validate_ipv46_address` didn't prohibit leading
|
||||
zeros in octal literals. If you used such values you could suffer from
|
||||
indeterminate SSRF, RFI, and LFI attacks.
|
||||
|
||||
:func:`~django.core.validators.validate_ipv4_address` and
|
||||
:func:`~django.core.validators.validate_ipv46_address` validators were not
|
||||
affected on Python 3.9.5+.
|
||||
|
|
|
@ -17,3 +17,16 @@ the existence but also the file contents would have been exposed.
|
|||
|
||||
As a mitigation, path sanitation is now applied and only files within the
|
||||
template root directories can be loaded.
|
||||
|
||||
CVE-2021-33571: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses
|
||||
===========================================================================================================================
|
||||
|
||||
:class:`~django.core.validators.URLValidator`,
|
||||
:func:`~django.core.validators.validate_ipv4_address`, and
|
||||
:func:`~django.core.validators.validate_ipv46_address` didn't prohibit leading
|
||||
zeros in octal literals. If you used such values you could suffer from
|
||||
indeterminate SSRF, RFI, and LFI attacks.
|
||||
|
||||
:func:`~django.core.validators.validate_ipv4_address` and
|
||||
:func:`~django.core.validators.validate_ipv46_address` validators were not
|
||||
affected on Python 3.9.5+.
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue