Описание
The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL.
Ссылки
- Third Party Advisory
- Broken Link
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- PatchVendor Advisory
- Third Party Advisory
- Broken Link
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.2 (исключая)
Одно из
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:1.4:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.02072
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
ubuntu
почти 14 лет назад
The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL.
debian
почти 14 лет назад
The (1) django.http.HttpResponseRedirect and (2) django.http.HttpRespo ...
EPSS
Процентиль: 80%
0.02072
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79