Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fq8-4pv5-5w5c

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Django cross-site scripting (XSS) attack via user-supplied redirect URLs

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.4.20

1.4.20

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.5, < 1.6.11

1.6.11

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.7, < 1.7.7

1.7.7

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.8a1, < 1.8c1

1.8c1

EPSS

Процентиль: 86%
0.03149
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

redhat
больше 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

nvd
около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

debian
около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1. ...

EPSS

Процентиль: 86%
0.03149
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79