Lucene search

K
redhatcveRedhat.comRH:CVE-2019-12781
HistoryApr 07, 2020 - 11:36 a.m.

CVE-2019-12781

2020-04-0711:36:06
redhat.com
access.redhat.com
9

0.01 Low

EPSS

Percentile

83.5%

An HTTP detection flaw was discovered in Django. If deployed behind a reverse-proxy connecting to Django via HTTPS, django.http.HttpRequest.scheme() incorrectly detected client requests made using HTTP as using HTTPS. This resulted in incorrect results for is_secure() and build_absolute_uri(), and HTTP requests were not correctly redirected to HTTPS in accordance with SECURE_SSL_REDIRECT.