Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7234

Опубликовано: 04 апр. 2017
Источник: debian
EPSS Низкий

Описание

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed1:1.10.7-1package

Примечания

  • https://www.djangoproject.com/weblog/2017/apr/04/security-releases/

  • Fixed by (master): https://github.com/django/django/commit/a1f948b468b6621083a03b0d53432341b7a4d753

EPSS

Процентиль: 55%
0.00321
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 8 лет назад

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.

CVSS3: 4.7
redhat
около 8 лет назад

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.

CVSS3: 6.1
nvd
около 8 лет назад

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.

CVSS3: 6.1
github
больше 6 лет назад

Django open redirect

suse-cvrf
около 7 лет назад

Security update for python-Django

EPSS

Процентиль: 55%
0.00321
Низкий