Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0480

Опубликовано: 20 авг. 2014
Источник: redhat
CVSS2: 4.3

Описание

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-djangoAffected
Red Hat OpenStack Platform 4Django14Affected
Red Hat Subscription Asset ManagerDjangoWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1129950Django: reverse() can generate URLs pointing to other hosts, leading to phishing attacks

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

nvd
почти 12 лет назад

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

debian
почти 12 лет назад

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x ...

CVSS3: 7.5
github
около 4 лет назад

Django Incorrectly Validates URLs

4.3 Medium

CVSS2