Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before...
Vulnerability Description
Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7233
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securitytracker.com/id/1038177
- https://access.redhat.com/errata/RHSA-2017:1596
- http://www.securityfocus.com/bid/97406
- https://access.redhat.com/errata/RHSA-2017:3093
- http://www.debian.org/security/2017/dsa-3835
- https://access.redhat.com/errata/RHSA-2017:1445
- https://access.redhat.com/errata/RHSA-2017:1451
- https://access.redhat.com/errata/RHSA-2018:2927
- https://access.redhat.com/errata/RHSA-2017:1470
- https://www.djangoproject.com/weblog/2017/apr/04/security-releases/
- https://access.redhat.com/errata/RHSA-2017:1462
More from djangoproject
View All →Affected Vendor
djangoproject
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.