Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv98-g628-m9x5

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Django Cross-site Scripting Vulnerability

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a \njavascript: URL.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.4.18

1.4.18

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.6, < 1.6.10

1.6.10

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.7, < 1.7.3

1.7.3

EPSS

Процентиль: 84%
0.02316
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

redhat
больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

nvd
больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

debian
больше 10 лет назад

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6 ...

EPSS

Процентиль: 84%
0.02316
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79