Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3498

Опубликовано: 07 янв. 2019
Источник: redhat
CVSS3: 4.3

Описание

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.

Отчет

This issue affects the versions of python-django as shipped with Red Hat Update Infrastructure 3. Even though the Red Hat Update Appliance ships python-django, the application is not accessible by default because of the firewall rules, thus this flaw cannot be used. However, it can be triggered on the Content Delivery Systems. Red Hat Satellite is not affected, since python-django is only used on Pulp API, which only returns JSON data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2python-djangoAffected
Red Hat Ceph Storage 3python-djangoAffected
Red Hat Certification for Red Hat Enterprise Linux 7python-djangoAffected
Red Hat OpenStack Platform 10 (Newton)python-djangoFix deferred
Red Hat OpenStack Platform 13 (Queens)python-djangoFix deferred
Red Hat OpenStack Platform 14 (Rocky)python-djangoFix deferred
Red Hat OpenStack Platform 8 (Liberty)python-djangoWill not fix
Red Hat OpenStack Platform 8 (Liberty) Operational Toolspython-djangoWill not fix
Red Hat OpenStack Platform 9 (Mitaka)python-djangoFix deferred
Red Hat OpenStack Platform 9 (Mitaka) Operational Toolspython-djangoFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-99
https://bugzilla.redhat.com/show_bug.cgi?id=1663722python-django: Content spoofing via URL path in default 404 page

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.

CVSS3: 6.5
nvd
больше 6 лет назад

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.

CVSS3: 6.5
debian
больше 6 лет назад

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before ...

CVSS3: 6.5
github
больше 6 лет назад

Improper Input Validation in Django

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость библиотеки Django для языка программирования Python, позволяющая нарушителю нарушить целостность защищаемой информации

4.3 Medium

CVSS3