Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-3730
HistoryMay 16, 2014 - 12:00 a.m.

CVE-2014-3730

2014-05-1600:00:00
ubuntu.com
ubuntu.com
25

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.2%

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5
before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly
validate URLs, which allows remote attackers to conduct open redirect
attacks via a malformed URL, as demonstrated by
“http:\\djangoproject.com.”

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchpython-django< 1.1.1-2ubuntu1.12UNKNOWN
ubuntu12.04noarchpython-django< 1.3.1-4ubuntu1.11UNKNOWN
ubuntu12.10noarchpython-django< 1.4.1-2ubuntu0.7UNKNOWN
ubuntu13.10noarchpython-django< 1.5.4-1ubuntu1.3UNKNOWN
ubuntu14.04noarchpython-django< 1.6.1-2ubuntu0.3UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.2%