Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13596

Опубликовано: 03 июн. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

A flaw was found in Django, where the query parameters for the admin widget ForeignKeyRawIdWidget were not properly URL encoded. This flaw allows an attacker to perform a Cross-site scripting (XSS) attack. The highest threat from this vulnerability is to confidentiality.

Отчет

The following products ship the flawed code, however they do not make use of ForeignKeyRawIdWidget and are therefore not vulnerable to this flaw:

  • Red Hat Satellite 6
  • Red Hat Update Infrastructure 3
  • Red Hat OpenStack Platform 13, 15, & 16
  • Red Hat Gluster Storage 3 The version of python-django shipped with Red Hat Ceph Storage(RHCS) was used with calamari and graphite which are no more supported, hence the django package will not be fixed for RHCS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2python-djangoOut of support scope
Red Hat Ceph Storage 3python-djangoWill not fix
Red Hat OpenStack Platform 10 (Newton)python-djangoOut of support scope
Red Hat OpenStack Platform 13 (Queens)python-djangoFix deferred
Red Hat OpenStack Platform 15 (Stein)python-djangoFix deferred
Red Hat OpenStack Platform 15 (Stein)python-django20Out of support scope
Red Hat OpenStack Platform 16 (Train)python-djangoFix deferred
Red Hat Satellite 6python-djangoWill not fix
Red Hat Storage 3python-djangoAffected
Red Hat Update Infrastructure 3 for Cloud Providerspython-djangoFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1843625django: possible XSS via admin ForeignKeyRawIdWidget

EPSS

Процентиль: 77%
0.0108
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
nvd
около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
debian
около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0 ...

CVSS3: 6.1
github
около 5 лет назад

XSS in Django

fstec
около 5 лет назад

Уязвимость реализации функции ForeignKeyRawIdWidget библиотеки Django, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 77%
0.0108
Низкий

6.5 Medium

CVSS3