Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2317

Опубликовано: 18 мар. 2015
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-djangoFix deferred
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-djangoFix deferred
Red Hat OpenStack Platform 4Django14Will not fix
Red Hat Subscription Asset ManagerDjangoWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1202818Django: possible XSS attack via user-supplied redirect URLs

EPSS

Процентиль: 86%
0.03149
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

nvd
около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

debian
около 10 лет назад

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1. ...

CVSS3: 6.1
github
около 3 лет назад

Django cross-site scripting (XSS) attack via user-supplied redirect URLs

EPSS

Процентиль: 86%
0.03149
Низкий

2.6 Low

CVSS2