High severity8.8NVD Advisory· Published Aug 3, 2022· Updated Jun 17, 2026
CVE-2022-36359
CVE-2022-36359
Description
An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | < 3.2.15 | 3.2.15 |
DjangoPyPI | >= 4.0, < 4.0.7 | 4.0.7 |
Affected products
13cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*range: >=3.2,<3.2.15
- (no CPE)
- osv-coords10 versionspkg:bitnami/djangopkg:pypi/djangopkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django5&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Django&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/python-Django&distro=SUSE%20Package%20Hub%2015%20SP4
>= 3.2.0, < 3.2.15+ 9 more
- (no CPE)range: >= 3.2.0, < 3.2.15
- (no CPE)range: < 3.2.15
- (no CPE)range: < 2.2.28-bp153.2.3.1
- (no CPE)range: < 2.2.28-bp154.2.3.3
- (no CPE)range: < 4.1-1.1
- (no CPE)range: < 4.2.14-1.1
- (no CPE)range: < 5.2.16-1.1
- (no CPE)range: < 6.0-1.1
- (no CPE)range: < 2.2.28-bp153.2.3.1
- (no CPE)range: < 2.2.28-bp154.2.3.3
Patches
Vulnerability mechanics
References
19- www.openwall.com/lists/oss-security/2022/08/03/1nvdMailing ListPatchThird Party AdvisoryWEB
- docs.djangoproject.com/en/4.0/releases/security/nvdNot ApplicablePatchVendor Advisory
- www.djangoproject.com/weblog/2022/aug/03/security-releases/nvdPatchVendor Advisory
- github.com/advisories/GHSA-8x94-hmjh-97hqghsaADVISORY
- groups.google.com/g/django-announce/c/8cz--gvaJr4nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-36359ghsaADVISORY
- security.netapp.com/advisory/ntap-20220915-0008/nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5254nvdThird Party AdvisoryWEB
- docs.djangoproject.com/en/4.0/releases/securityghsaWEB
- github.com/django/django/commit/b3e4494d759202a3b6bf247fd34455bf13be5b80ghsaWEB
- github.com/django/django/commit/b7d9529cbe0af4adabb6ea5d01ed8dcce3668fb3ghsaWEB
- github.com/django/django/commit/bd062445cffd3f6cc6dcd20d13e2abed818fa173ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2022-245.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IKghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQIghsaWEB
- security.netapp.com/advisory/ntap-20220915-0008ghsaWEB
- www.djangoproject.com/weblog/2022/aug/03/security-releasesghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI/nvd
News mentions
0No linked articles in our index yet.