CVE-2021-31542 | Django up to 2.2.20/3.1.8/3.2.0 File Name MultiPartParser/UploadedFile/FieldFile pathname traversal (Nessus ID 211197)
A vulnerability was found in Django up to 2.2.20/3.1.8/3.2.0. It has been declared as critical. Affected by this vulnerability is the function MultiPartParser/UploadedFile/FieldFile of the component File Name Handler. The manipulation leads to pathname traversal.
This vulnerability is known as CVE-2021-31542. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.