Lucene search

K
osvGoogleOSV:PYSEC-2014-20
HistoryMay 16, 2014 - 3:55 p.m.

PYSEC-2014-20

2014-05-1615:55:00
Google
osv.dev
23

EPSS

0.005

Percentile

75.2%

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by “http:\\djangoproject.com.”