django-downloadview is vulnerable to Reflected File Download
75
High Risk
Affected versions of the package are vulnerable to reflected file download on specially named files. ASCII filenames are quoted and should escape sequences in the filename to prevent breaking out of the quoted header value. The UTF-8 version is immune because it's not quoted.
You are affected if you are using a version that falls within the vulnerable range.
django-downloadview is vulnerable to Reflected File Download in versions 1.5.0 - 2.3.0.
Upgrade the django-downloadview library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant