Publish GHSA-8x94-hmjh-97hq

This commit is contained in:
advisory-database[bot]
2024-12-18 22:09:54 +00:00
parent 65a5e18ef3
commit b86363fd18
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8x94-hmjh-97hq",
"modified": "2024-09-03T14:59:09Z",
"modified": "2024-12-18T22:08:23Z",
"published": "2022-08-11T14:49:12Z",
"aliases": [
"CVE-2022-36359"
],
"summary": "Django vulnerable to Reflected File Download attack ",
"summary": "Django vulnerable to Reflected File Download attack",
"details": "An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.",
"severity": [
{