Vulnerabilities (CVE)

Filtered by vendor Django-s3file Project
Filtered by product Django-s3file
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24840 1 Django-s3file Project 1 Django-s3file 2024-11-21 7.5 HIGH 9.1 CRITICAL
django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set, traversal was limited to that location only. The issue was discovered by the maintainer. There were no reports of the vulnerability being known to or exploited by a third party, prior to the release of the patch. The vulnerability has been fixed in version 5.5 ...

Show More