Description
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.
Remediation
References
Related Vulnerabilities
WordPress Plugin Responsive Cookie Consent Cross-Site Scripting (1.7)
WordPress Plugin SportsPress-Sports Club & League Manager Cross-Site Scripting (2.7.1)
WordPress Plugin WP Google Maps Cross-Site Scripting (7.11.34)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-7061)