Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-36359
Description:An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user- supplied input.
Test IDs: 1.3.6.1.4.1.25623.1.0.833461   1.3.6.1.4.1.25623.1.0.126100   1.3.6.1.4.1.25623.1.0.126101   1.3.6.1.4.1.25623.1.0.845467  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-36359
Debian Security Information: DSA-5254 (Google Search)
https://www.debian.org/security/2022/dsa-5254
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI/
https://docs.djangoproject.com/en/4.0/releases/security/
https://groups.google.com/g/django-announce/c/8cz--gvaJr4
http://www.openwall.com/lists/oss-security/2022/08/03/1




© 1998-2025 E-Soft Inc. All rights reserved.