Описание
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the django.views.static.serve()
view could redirect to any other domain, aka an open redirect vulnerability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ceph Storage 1.3 | python-django | Will not fix | ||
Red Hat Ceph Storage 2 | python-django | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | python-django | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | python-django | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-django | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | python-django | Not affected | ||
Red Hat OpenStack Platform 10 (Newton) | python-django | Not affected | ||
Red Hat OpenStack Platform 10 (Newton) Operational Tools | python-django | Not affected | ||
Red Hat OpenStack Platform 8 (Liberty) | python-django | Not affected | ||
Red Hat OpenStack Platform 8 (Liberty) Operational Tools | python-django | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4.7 Medium
CVSS3
Связанные уязвимости
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before ...
EPSS
4.7 Medium
CVSS3