PT-2017-17596 · Django Software Foundation+2 · Django+2

Phithon

·

Published

2017-04-04

·

Updated

2026-01-03

·

CVE-2017-7234

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Django versions 1.8 through 1.8.18 Django versions 1.9 through 1.9.13 Django versions 1.10 through 1.10.7
Description A maliciously crafted URL to a Django site using the django.views.static.serve() view could redirect to any other domain. This issue is also known as an open redirect.
Recommendations For Django versions 1.8 through 1.8.17, update to version 1.8.18. For Django versions 1.9 through 1.9.12, update to version 1.9.13. For Django versions 1.10 through 1.10.6, update to version 1.10.7.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1458
CVE-2017-7234
DLA-885-1
DSA-3835-1
GHSA-H4HV-M4H4-MHWG
MGASA-2017-0106
OPENSUSE-SU-2018:0632-1
OPENSUSE-SU-2023:0077-1
OPENSUSE-SU-2024:11205-1
OPENSUSE-SU-2024:13887-1
OPENSUSE-SU-2024:14208-1
OPENSUSE-SU-2026:10005-1
PYSEC-2017-10
SUSE-SU-2018:0973-1
SUSE-SU-2018:1102-1
USN-3254-1

Affected Products

Alt Linux
Django
Ubuntu