Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6c7v-2f49-8h26

Опубликовано: 03 июл. 2019
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Django Incorrect HTTP detection with reverse-proxy connecting via HTTPS

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 2.1, < 2.1.10

2.1.10

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 2.2, < 2.2.3

2.2.3

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.11, < 1.11.22

1.11.22

EPSS

Процентиль: 84%
0.02419
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 6 лет назад

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.

CVSS3: 4.8
redhat
почти 6 лет назад

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.

CVSS3: 5.3
nvd
почти 6 лет назад

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.

CVSS3: 5.3
debian
почти 6 лет назад

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1. ...

CVSS3: 5.3
fstec
почти 6 лет назад

Уязвимость компонента django.http.HttpRequest.scheme библиотеки Django для языка программирования Python, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 84%
0.02419
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-319