The ``django.utils.archive.extract()`` function, used by ``startapp --template`` and ``startproject --template``, allowed directory-traversal via an archive with absolute paths or relative paths with dot segments.
Created django:1.6/python-django tracking bugs for this issue: Affects: fedora-all [bug 1923735] Created python-django tracking bugs for this issue: Affects: epel-all [bug 1923732] Affects: fedora-all [bug 1923733] Affects: openstack-rdo [bug 1923734]
Upstream fix: https://github.com/django/django/commit/05413afa8c18cdb978fcdf470e09f7a12b234a23 [master] https://github.com/django/django/commit/f944f79e555c91571192022a6bb9ddf2178db7ed [3.2] https://github.com/django/django/commit/02e6592835b4559909aa3aaaf67988fef435f624 [3.1] https://github.com/django/django/commit/52e409ed17287e9aabda847b6afe58be2fa9f86a [3.0] https://github.com/django/django/commit/21e7622dec1f8612c85c2fc37fe8efbfd3311e37 [2.2]
This issue has been addressed in the following products: Red Hat Automation Hub 4.2 for RHEL 7 Red Hat Automation Hub 4.2 for RHEL 8 Via RHSA-2021:0781 https://access.redhat.com/errata/RHSA-2021:0781
This issue has been addressed in the following products: Red Hat Ansible Tower 3.8 for RHEL 7 Via RHSA-2021:0780 https://access.redhat.com/errata/RHSA-2021:0780
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-3281
Statement: The following products ship affected version of python-django, however the vulnerable function archive.extract() is currently not used in any part of the product and hence this issue has been rated as having a security impact of Low: * Red Hat Gluster Storage 3 * Red Hat Update Infrastructure 3 In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-twisted package.
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2021:3490 https://access.redhat.com/errata/RHSA-2021:3490
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2021:5070 https://access.redhat.com/errata/RHSA-2021:5070