An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-django | Aug 22, 2024 | Aug 3, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Aug 3, 2022 |
| Debian | — | Upgrade python-django | Nov 4, 2022 | Aug 3, 2022 |
| Freebsd | — | Upgrade py310-django40Upgrade py38-django32Upgrade py39-django40Upgrade py310-django32Upgrade py39-django32Upgrade py38-django40 | Nov 4, 2022 | Aug 5, 2022 |
| Gentoo Linux | — | Upgrade dev-python/django. | Sep 18, 2025 | Sep 17, 2025 |
| Suse | — | Upgrade python3-django | Oct 26, 2022 | Aug 3, 2022 |
| Ubuntu | — | Upgrade python3-django | Aug 5, 2022 | Aug 3, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub