Lucene search

K
redhatRedHatRHSA-2017:3093
HistoryOct 31, 2017 - 5:11 p.m.

(RHSA-2017:3093) Moderate: python-django security update

2017-10-3117:11:39
access.redhat.com
76

0.004 Low

EPSS

Percentile

72.6%

Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don’t Repeat Yourself) principle.

Security Fix(es):

  • A redirect flaw, where the is_safe_url() function did not correctly sanitize numeric-URL user input, was found in python-django. A remote attacker could exploit this flaw to perform XSS attacks against the OpenStack dashboard. (CVE-2017-7233)

Red Hat would like to thank the Django project for reporting this issue.