CVE-2022-22818
03.02.2022, 02:15
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
Vendor | Product | Version |
---|---|---|
djangoproject | django | 2.2 ≤ 𝑥 < 2.2.27 |
djangoproject | django | 3.2 ≤ 𝑥 < 3.2.12 |
djangoproject | django | 4.0 ≤ 𝑥 < 4.0.2 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References