Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3730

Опубликовано: 16 мая 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\djangoproject.com."

РелизСтатусПримечание
devel

released

1.6.1-2ubuntu0.3
esm-infra-legacy/trusty

not-affected

1.6.1-2ubuntu0.3
lucid

released

1.1.1-2ubuntu1.12
precise

released

1.3.1-4ubuntu1.11
quantal

released

1.4.1-2ubuntu0.7
saucy

released

1.5.4-1ubuntu1.3
trusty

released

1.6.1-2ubuntu0.3
trusty/esm

not-affected

1.6.1-2ubuntu0.3
upstream

released

1.6.5-1

Показывать по

EPSS

Процентиль: 76%
0.00988
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

nvd
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

debian
около 11 лет назад

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, ...

CVSS3: 7.5
github
около 3 лет назад

Django Allows Open Redirects

EPSS

Процентиль: 76%
0.00988
Низкий

4.3 Medium

CVSS2