Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3730

Опубликовано: 14 мая 2014
Источник: redhat
CVSS2: 5

Описание

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\djangoproject.com."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3DjangoWill not fix
Red Hat OpenStack Platform 4DjangoWill not fix
Red Hat Subscription Asset ManagerDjangoWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1097505Django: insufficient URL validation could lead to redirects

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

nvd
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

debian
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, ...

CVSS3: 7.5
github
около 3 лет назад

Django Allows Open Redirects

5 Medium

CVSS2