Django Software Foundation · Django · CVE-2017-7234
**Name of the Vulnerable Software and Affected Versions**
Django versions 1.8 through 1.8.18
Django versions 1.9 through 1.9.13
Django versions 1.10 through 1.10.7
**Description**
A maliciously crafted URL to a Django site using the `django.views.static.serve()` view could redirect to any other domain. This issue is also known as an open redirect.
**Recommendations**
For Django versions 1.8 through 1.8.17, update to version 1.8.18.
For Django versions 1.9 through 1.9.12, update to version 1.9.13.
For Django versions 1.10 through 1.10.6, update to version 1.10.7.