Логотип exploitDog
bind:"GHSA-37hp-765x-j95x" OR bind:"CVE-2017-7233"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-37hp-765x-j95x" OR bind:"CVE-2017-7233"

Количество 7

Количество 7

github логотип

GHSA-37hp-765x-j95x

больше 6 лет назад

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-7233

около 8 лет назад

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2017-7233

около 8 лет назад

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-7233

около 8 лет назад

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-7233

около 8 лет назад

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 re ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:0826-1

около 7 лет назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:0824-1

около 7 лет назад

Security update for python3-Django

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37hp-765x-j95x

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

CVSS3: 6.1
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 re ...

CVSS3: 6.1
1%
Низкий
около 8 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0826-1

Security update for python-Django

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0824-1

Security update for python3-Django

около 7 лет назад

Уязвимостей на страницу