From b86363fd1867252eb68d03614960bab1ed545f16 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 18 Dec 2024 22:09:54 +0000 Subject: [PATCH] Publish GHSA-8x94-hmjh-97hq --- .../2022/08/GHSA-8x94-hmjh-97hq/GHSA-8x94-hmjh-97hq.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2022/08/GHSA-8x94-hmjh-97hq/GHSA-8x94-hmjh-97hq.json b/advisories/github-reviewed/2022/08/GHSA-8x94-hmjh-97hq/GHSA-8x94-hmjh-97hq.json index 45c6091c469..e23da87f89b 100644 --- a/advisories/github-reviewed/2022/08/GHSA-8x94-hmjh-97hq/GHSA-8x94-hmjh-97hq.json +++ b/advisories/github-reviewed/2022/08/GHSA-8x94-hmjh-97hq/GHSA-8x94-hmjh-97hq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8x94-hmjh-97hq", - "modified": "2024-09-03T14:59:09Z", + "modified": "2024-12-18T22:08:23Z", "published": "2022-08-11T14:49:12Z", "aliases": [ "CVE-2022-36359" ], - "summary": "Django vulnerable to Reflected File Download attack ", + "summary": "Django vulnerable to Reflected File Download attack", "details": "An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.", "severity": [ {