mirror of
https://github.com/django/django.git
synced 2025-10-24 14:16:09 +00:00
Fixed CVE-2021-33203 -- Fixed potential path-traversal via admindocs' TemplateDetailView.
This commit is contained in:
committed by
Carlton Gibson
parent
f66ae7a2d5
commit
46572de2e9
@@ -154,6 +154,22 @@ class AdminDocViewTests(TestDataMixin, AdminDocsTestCase):
|
||||
self.assertEqual(response.status_code, 200)
|
||||
|
||||
|
||||
@unittest.skipUnless(utils.docutils_is_available, 'no docutils installed.')
|
||||
class AdminDocViewDefaultEngineOnly(TestDataMixin, AdminDocsTestCase):
|
||||
|
||||
def setUp(self):
|
||||
self.client.force_login(self.superuser)
|
||||
|
||||
def test_template_detail_path_traversal(self):
|
||||
cases = ['/etc/passwd', '../passwd']
|
||||
for fpath in cases:
|
||||
with self.subTest(path=fpath):
|
||||
response = self.client.get(
|
||||
reverse('django-admindocs-templates', args=[fpath]),
|
||||
)
|
||||
self.assertEqual(response.status_code, 400)
|
||||
|
||||
|
||||
@override_settings(TEMPLATES=[{
|
||||
'NAME': 'ONE',
|
||||
'BACKEND': 'django.template.backends.django.DjangoTemplates',
|
||||
|
Reference in New Issue
Block a user