Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vq3h-3q7v-9prw

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

Django Allows Open Redirects

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\djangoproject.com."

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.4, < 1.4.13

1.4.13

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.5, < 1.5.8

1.5.8

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.6, < 1.6.5

1.6.5

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.7a1, < 1.7b4

1.7b4

EPSS

Процентиль: 76%
0.00988
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

redhat
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

nvd
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

debian
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, ...

EPSS

Процентиль: 76%
0.00988
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20