Lucene search

K
cvelistDebianCVELIST:CVE-2014-3730
HistoryMay 16, 2014 - 3:00 p.m.

CVE-2014-3730

2014-05-1615:00:00
debian
www.cve.org
7

AI Score

6.2

Confidence

Low

EPSS

0.005

Percentile

75.2%

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by “http:\\djangoproject.com.”

AI Score

6.2

Confidence

Low

EPSS

0.005

Percentile

75.2%