CVE-2021-45116
medium
CVSS v3
—
CVSS v2
—
VIR risk
5.5
Description
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method call, if passed a suitably crafted key.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-45116
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2022:5498
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-45116.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| rocky | 8 | fixed | |
| debian | bookworm | fixed | 2:3.2.11-1 |
| debian | bullseye | fixed | 2:2.2.26-1~deb11u1 |
| debian | forky | fixed | 2:3.2.11-1 |
| debian | sid | fixed | 2:3.2.11-1 |
| debian | trixie | fixed | 2:3.2.11-1 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-45116
- https://github.com/django/django/commit/2a8ec7f546d6d5806e221ec948c5146b55bd7489
- https://github.com/django/django/commit/c7fe895bca06daf12cc1670b56eaf72a1ef27a16
- https://github.com/django/django/commit/c9f648ccfac5ab90fb2829a66da4f77e68c7f93a
- https://docs.djangoproject.com/en/4.0/releases/security
- https://github.com/advisories/GHSA-8c5j-9r9f-c6w8
- https://github.com/django/django
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2022-2.yaml
- https://groups.google.com/forum/#!forum/django-announce
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV
- https://security.netapp.com/advisory/ntap-20220121-0005
- https://www.djangoproject.com/weblog/2022/jan/04/security-releases
- https://docs.djangoproject.com/en/4.0/releases/security/
- https://www.djangoproject.com/weblog/2022/jan/04/security-releases/
- https://www.suse.com/security/cve/CVE-2021-45116.html
- https://errata.rockylinux.org/RLSA-2022:5498
- https://security-tracker.debian.org/tracker/CVE-2021-45116
Verify integrity in audit chain (admin only). AS-IS.