Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-32052
Description:In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.
Test IDs: 1.3.6.1.4.1.25623.1.0.145923   1.3.6.1.4.1.25623.1.0.145922  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-32052
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE/
http://www.openwall.com/lists/oss-security/2021/05/06/1
https://docs.djangoproject.com/en/3.2/releases/security/
https://groups.google.com/forum/#!forum/django-announce
https://www.djangoproject.com/weblog/2021/may/06/security-releases/




© 1998-2025 E-Soft Inc. All rights reserved.