CVE-2022-36359Download of Code Without Integrity Check in Django

Severity
8.8HIGHNVD
EPSS
0.8%
top 26.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateAug 11

Description

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDdjangoproject/django3.23.2.15+1
PyPIdjangoproject/django4.04.0.7+1

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

6
GHSA
django-sendfile2 before 0.7.0 contains reflected file download vulnerability2022-08-11
OSV
Django vulnerable to Reflected File Download attack2022-08-11
OSV
django-sendfile2 before 0.7.0 contains reflected file download vulnerability2022-08-11
GHSA
Django vulnerable to Reflected File Download attack2022-08-11
CVEList
CVE-2022-36359: An issue was discovered in the HTTP FileResponse class in Django 32022-08-03

📋Vendor Advisories

2
Ubuntu
Django vulnerability2022-08-04
Debian
CVE-2022-36359: python-django - An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2....2022
CVE-2022-36359 — Djangoproject Django vulnerability | cvebase