Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-07A8C8D3E73A10C91CF5377E3FAA92C4
HistoryMay 14, 2022 - 12:00 a.m.

Improper Input Validation

2022-05-1400:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
9

0.005 Low

EPSS

Percentile

75.3%

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.