PT-2017-17596 · Django Software Foundation+2 · Django+2

Phithon

·

Publicado

2017-04-04

·

Atualizado

2026-01-03

·

CVE-2017-7234

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Django versions 1.8 through 1.8.18 Django versions 1.9 through 1.9.13 Django versions 1.10 through 1.10.7
Description A maliciously crafted URL to a Django site using the django.views.static.serve() view could redirect to any other domain. This issue is also known as an open redirect.
Recommendations For Django versions 1.8 through 1.8.17, update to version 1.8.18. For Django versions 1.9 through 1.9.12, update to version 1.9.13. For Django versions 1.10 through 1.10.6, update to version 1.10.7.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1458
CVE-2017-7234
DLA-885-1
DSA-3835-1
GHSA-H4HV-M4H4-MHWG
MGASA-2017-0106
OPENSUSE-SU-2018:0632-1
OPENSUSE-SU-2023:0077-1
OPENSUSE-SU-2024:11205-1
OPENSUSE-SU-2024:13887-1
OPENSUSE-SU-2024:14208-1
OPENSUSE-SU-2026:10005-1
PYSEC-2017-10
SUSE-SU-2018:0973-1
SUSE-SU-2018:1102-1
USN-3254-1

Produtos afetados

Alt Linux
Django
Ubuntu