First published: Tue Apr 04 2017(Updated: )
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/django | >=1.8<1.8.18 | 1.8.18 |
pip/django | >=1.9<1.9.13 | 1.9.13 |
pip/django | >=1.10<1.10.7 | 1.10.7 |
Django | =1.8.0 | |
Django | =1.8.0-a1 | |
Django | =1.8.0-b1 | |
Django | =1.8.0-b2 | |
Django | =1.8.0-c1 | |
Django | =1.8.1 | |
Django | =1.8.2 | |
Django | =1.8.3 | |
Django | =1.8.4 | |
Django | =1.8.5 | |
Django | =1.8.6 | |
Django | =1.8.7 | |
Django | =1.8.8 | |
Django | =1.8.9 | |
Django | =1.8.10 | |
Django | =1.8.11 | |
Django | =1.8.12 | |
Django | =1.8.13 | |
Django | =1.8.14 | |
Django | =1.8.15 | |
Django | =1.8.16 | |
Django | =1.8.17 | |
Django | =1.9 | |
Django | =1.9-a1 | |
Django | =1.9-b1 | |
Django | =1.9-rc1 | |
Django | =1.9-rc2 | |
Django | =1.9.1 | |
Django | =1.9.2 | |
Django | =1.9.3 | |
Django | =1.9.4 | |
Django | =1.9.5 | |
Django | =1.9.6 | |
Django | =1.9.7 | |
Django | =1.9.8 | |
Django | =1.9.9 | |
Django | =1.9.10 | |
Django | =1.9.11 | |
Django | =1.9.12 | |
Django | =1.10.0 | |
Django | =1.10.0-a1 | |
Django | =1.10.0-b1 | |
Django | =1.10.0-rc1 | |
Django | =1.10.1 | |
Django | =1.10.2 | |
Django | =1.10.3 | |
Django | =1.10.4 | |
Django | =1.10.5 | |
Django | =1.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7234 is classified as a medium severity vulnerability due to the potential for open redirects.
To remediate CVE-2017-7234, upgrade Django to version 1.10.7, 1.9.13, or 1.8.18 or later.
CVE-2017-7234 affects Django versions 1.10 prior to 1.10.7, 1.9 prior to 1.9.13, and 1.8 prior to 1.8.18.
An attacker could exploit CVE-2017-7234 to redirect users to potentially malicious external websites.
To mitigate CVE-2017-7234, consider disabling the use of django.views.static.serve() or implementing strict validation on redirect URLs.