vulnerability
Arch Linux: Cross-site Scripting (CVE-2022-22818)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:N/I:P/A:N) | Feb 3, 2022 | Jul 11, 2025 | Nov 27, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Feb 3, 2022
Added
Jul 11, 2025
Modified
Nov 27, 2025
Description
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
Solution
arch-linux-upgrade-latest
References
- CVE-2022-22818
- https://attackerkb.com/topics/CVE-2022-22818
- URL-https://docs.djangoproject.com/en/4.0/releases/security/
- URL-https://groups.google.com/forum/#%21forum/django-announce
- URL-https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/
- URL-https://security.netapp.com/advisory/ntap-20220221-0003/
- URL-https://www.debian.org/security/2022/dsa-5254
- URL-https://www.djangoproject.com/weblog/2022/feb/01/security-releases/
- CWE-79
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.