Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14574

Опубликовано: 01 авг. 2018
Источник: redhat
CVSS3: 4.7
EPSS Средний

Описание

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

When using the django.middleware.common.CommonMiddleware class with the APPEND_SLASH setting enabled, Django projects which accept paths ending in a slash may be vulnerable to an unvalidated HTTP redirect.

Отчет

This issue did not affect the versions of python-django as shipped with Red Hat Update Infrastructure 3 as the vulnerable code was introduced in a newer version of the package. Subscription Asset Manager is now in a reduced support phase receiving only Critical impact security fixes. This issue has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. Although Red Hat Satellite 6 contains the vulnerable component, it is not affected by this flaw since the condition to exploit the vulnerability cannot be satisfied. In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-django package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2python-djangoAffected
Red Hat Ceph Storage 3python-djangoAffected
Red Hat Certification for Red Hat Enterprise Linux 7python-djangoNot affected
Red Hat OpenStack Platform 10 (Newton)python-djangoWill not fix
Red Hat OpenStack Platform 12 (Pike)python-djangoOut of support scope
Red Hat OpenStack Platform 13 (Queens)python-djangoWill not fix
Red Hat OpenStack Platform 14 (Rocky)python-djangoOut of support scope
Red Hat OpenStack Platform 8 (Liberty)python-djangoWill not fix
Red Hat OpenStack Platform 8 (Liberty) Operational Toolspython-djangoWill not fix
Red Hat OpenStack Platform 9 (Mitaka)python-djangoWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1609031django: Open redirect possibility in CommonMiddleware

EPSS

Процентиль: 94%
0.14743
Средний

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 7 лет назад

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

CVSS3: 6.1
nvd
почти 7 лет назад

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

CVSS3: 6.1
debian
почти 7 лет назад

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11 ...

suse-cvrf
почти 7 лет назад

Security update for python-Django

suse-cvrf
почти 7 лет назад

Security update for python-Django

EPSS

Процентиль: 94%
0.14743
Средний

4.7 Medium

CVSS3