Show plain JSON{"affected_release": [{"advisory": "RHSA-2024:6428", "cpe": "cpe:/a:redhat:ansible_automation_platform:2.4::el8", "package": "python3x-django-0:4.2.15-1.el8ap", "product_name": "Red Hat Ansible Automation Platform 2.4 for RHEL 8", "release_date": "2024-09-05T00:00:00Z"}, {"advisory": "RHSA-2024:6428", "cpe": "cpe:/a:redhat:ansible_automation_platform:2.4::el9", "package": "python-django-0:4.2.15-1.el9ap", "product_name": "Red Hat Ansible Automation Platform 2.4 for RHEL 9", "release_date": "2024-09-05T00:00:00Z"}, {"advisory": "RHSA-2024:9481", "cpe": "cpe:/a:redhat:openstack:18.0::el9", "package": "python-django-0:3.2.12-8.el9ost", "product_name": "Red Hat OpenStack Services on OpenShift 18.0", "release_date": "2024-11-13T00:00:00Z"}, {"advisory": "RHSA-2024:8906", "cpe": "cpe:/a:redhat:satellite:6.16::el8", "package": "python-django-0:4.2.16-1.el8pc", "product_name": "Red Hat Satellite 6.16 for RHEL 8", "release_date": "2024-11-05T00:00:00Z"}, {"advisory": "RHSA-2024:8906", "cpe": "cpe:/a:redhat:satellite_capsule:6.16::el8", "package": "python-django-0:4.2.16-1.el8pc", "product_name": "Red Hat Satellite 6.16 for RHEL 8", "release_date": "2024-11-05T00:00:00Z"}, {"advisory": "RHSA-2024:8906", "cpe": "cpe:/a:redhat:satellite:6.16::el9", "package": "python-django-0:4.2.16-1.el9pc", "product_name": "Red Hat Satellite 6.16 for RHEL 9", "release_date": "2024-11-05T00:00:00Z"}, {"advisory": "RHSA-2024:8906", "cpe": "cpe:/a:redhat:satellite_capsule:6.16::el9", "package": "python-django-0:4.2.16-1.el9pc", "product_name": "Red Hat Satellite 6.16 for RHEL 9", "release_date": "2024-11-05T00:00:00Z"}], "bugzilla": {"description": "python-django: Potential directory-traversal in django.core.files.storage.Storage.save()", "id": "2295937", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2295937"}, "csaw": false, "cvss3": {"cvss3_base_score": "4.3", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "status": "verified"}, "cwe": "CWE-22", "details": ["An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicating the file-path validations from the parent class, potentially allow directory traversal via certain inputs during a save() call. (Built-in Storage sub-classes are unaffected.)", "A vulnerability was found in Python-Django in the Derived classes of the django.core.files.storage.Storage base class that overrides the generate_filename() without replicating the file path validations existing in the parent class. This flaw allows potential directory traversal via certain inputs when calling save(). Built-in Storage sub-classes were not affected by this vulnerability."], "mitigation": {"lang": "en:us", "value": "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability."}, "name": "CVE-2024-39330", "package_state": [{"cpe": "cpe:/a:redhat:ansible_automation_platform", "fix_state": "Affected", "package_name": "ansible-tower", "product_name": "Red Hat Ansible Automation Platform 1.2"}, {"cpe": "cpe:/a:redhat:ansible_automation_platform:2", "fix_state": "Fix deferred", "package_name": "ansible-automation-platform-24/lightspeed-rhel8", "product_name": "Red Hat Ansible Automation Platform 2"}, {"cpe": "cpe:/a:redhat:ansible_automation_platform:2", "fix_state": "Fix deferred", "package_name": "automation-controller", "product_name": "Red Hat Ansible Automation Platform 2"}, {"cpe": "cpe:/a:redhat:certifications:1::el7", "fix_state": "Affected", "package_name": "python-django", "product_name": "Red Hat Certification for Red Hat Enterprise Linux 7"}, {"cpe": "cpe:/a:redhat:certifications:1::el8", "fix_state": "Affected", "package_name": "redhat-certification", "product_name": "Red Hat Certification for Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/a:redhat:certifications:1::el9", "fix_state": "Affected", "package_name": "redhat-certification", "product_name": "Red Hat Certification for Red Hat Enterprise Linux 9"}, {"cpe": "cpe:/a:redhat:discovery:1", "fix_state": "Affected", "package_name": "discovery-server-container", "product_name": "Red Hat Discovery"}, {"cpe": "cpe:/a:redhat:openstack:16.1", "fix_state": "Affected", "package_name": "python-django20", "product_name": "Red Hat OpenStack Platform 16.1"}, {"cpe": "cpe:/a:redhat:openstack:16.2", "fix_state": "Affected", "package_name": "python-django20", "product_name": "Red Hat OpenStack Platform 16.2"}, {"cpe": "cpe:/a:redhat:openstack:17.1", "fix_state": "Affected", "package_name": "python-django", "product_name": "Red Hat OpenStack Platform 17.1"}, {"cpe": "cpe:/a:redhat:storage:3", "fix_state": "Affected", "package_name": "python-django", "product_name": "Red Hat Storage 3"}, {"cpe": "cpe:/a:redhat:rhui:4::el8", "fix_state": "Fix deferred", "package_name": "python-django", "product_name": "Red Hat Update Infrastructure 4 for Cloud Providers"}], "public_date": "2024-07-09T14:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2024-39330\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-39330"], "threat_severity": "Low"}