Lucene search

K
githubGitHub Advisory DatabaseGHSA-VQ3H-3Q7V-9PRW
HistoryMay 14, 2022 - 2:09 a.m.

Django Allows Open Redirects

2022-05-1402:09:43
CWE-20
GitHub Advisory Database
github.com
14
django
open redirects
vulnerability
is_safe_url
attack
malformed url

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.2%

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by “http:\\djangoproject.com.”

Affected configurations

Vulners
Node
djangoRange<1.7b4
OR
djangoRange<1.6.5
OR
djangoRange<1.5.8
OR
djangoRange<1.4.13
VendorProductVersionCPE
*django*cpe:2.3:a:*:django:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.2%