Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
django-s3file: Relative path traversal
Vulnerability Description
django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into request.FILES. Depending on how files are handled, this may lead to confidentiality and integrity issues. This vulnerability is fixed in 7.0.2.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
django-s3file 路径遍历漏洞
Vulnerability Description
django-s3file是Johannes Maron个人开发者的一款用于Django和Amazon S3的轻量级文件上传输入的软件。 django-s3file 7.0.2之前版本存在路径遍历漏洞,该漏洞源于S3FileMiddleware相对路径遍历,可能导致攻击者从随机位置加载文件。
CVSS Information
N/A
Vulnerability Type
N/A