Lucene search

K
osvGoogleOSV:GHSA-VQ3H-3Q7V-9PRW
HistoryMay 14, 2022 - 2:09 a.m.

Django Allows Open Redirects

2022-05-1402:09:43
Google
osv.dev
11
django
open redirect
vulnerability
url validation
remote attackers
security patch

EPSS

0.005

Percentile

75.2%

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by “http:\\djangoproject.com.”