First published: Tue Apr 04 2017(Updated: )
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/django | >=1.8<1.8.18 | 1.8.18 |
pip/django | >=1.9<1.9.13 | 1.9.13 |
pip/django | >=1.10<1.10.7 | 1.10.7 |
Djangoproject Django | =1.8.0 | |
Djangoproject Django | =1.8.0-a1 | |
Djangoproject Django | =1.8.0-b1 | |
Djangoproject Django | =1.8.0-b2 | |
Djangoproject Django | =1.8.0-c1 | |
Djangoproject Django | =1.8.1 | |
Djangoproject Django | =1.8.2 | |
Djangoproject Django | =1.8.3 | |
Djangoproject Django | =1.8.4 | |
Djangoproject Django | =1.8.5 | |
Djangoproject Django | =1.8.6 | |
Djangoproject Django | =1.8.7 | |
Djangoproject Django | =1.8.8 | |
Djangoproject Django | =1.8.9 | |
Djangoproject Django | =1.8.10 | |
Djangoproject Django | =1.8.11 | |
Djangoproject Django | =1.8.12 | |
Djangoproject Django | =1.8.13 | |
Djangoproject Django | =1.8.14 | |
Djangoproject Django | =1.8.15 | |
Djangoproject Django | =1.8.16 | |
Djangoproject Django | =1.8.17 | |
Djangoproject Django | =1.9 | |
Djangoproject Django | =1.9-a1 | |
Djangoproject Django | =1.9-b1 | |
Djangoproject Django | =1.9-rc1 | |
Djangoproject Django | =1.9-rc2 | |
Djangoproject Django | =1.9.1 | |
Djangoproject Django | =1.9.2 | |
Djangoproject Django | =1.9.3 | |
Djangoproject Django | =1.9.4 | |
Djangoproject Django | =1.9.5 | |
Djangoproject Django | =1.9.6 | |
Djangoproject Django | =1.9.7 | |
Djangoproject Django | =1.9.8 | |
Djangoproject Django | =1.9.9 | |
Djangoproject Django | =1.9.10 | |
Djangoproject Django | =1.9.11 | |
Djangoproject Django | =1.9.12 | |
Djangoproject Django | =1.10.0 | |
Djangoproject Django | =1.10.0-a1 | |
Djangoproject Django | =1.10.0-b1 | |
Djangoproject Django | =1.10.0-rc1 | |
Djangoproject Django | =1.10.1 | |
Djangoproject Django | =1.10.2 | |
Djangoproject Django | =1.10.3 | |
Djangoproject Django | =1.10.4 | |
Djangoproject Django | =1.10.5 | |
Djangoproject Django | =1.10.6 | |
=1.8.0 | ||
=1.8.0-a1 | ||
=1.8.0-b1 | ||
=1.8.0-b2 | ||
=1.8.0-c1 | ||
=1.8.1 | ||
=1.8.2 | ||
=1.8.3 | ||
=1.8.4 | ||
=1.8.5 | ||
=1.8.6 | ||
=1.8.7 | ||
=1.8.8 | ||
=1.8.9 | ||
=1.8.10 | ||
=1.8.11 | ||
=1.8.12 | ||
=1.8.13 | ||
=1.8.14 | ||
=1.8.15 | ||
=1.8.16 | ||
=1.8.17 | ||
=1.9 | ||
=1.9-a1 | ||
=1.9-b1 | ||
=1.9-rc1 | ||
=1.9-rc2 | ||
=1.9.1 | ||
=1.9.2 | ||
=1.9.3 | ||
=1.9.4 | ||
=1.9.5 | ||
=1.9.6 | ||
=1.9.7 | ||
=1.9.8 | ||
=1.9.9 | ||
=1.9.10 | ||
=1.9.11 | ||
=1.9.12 | ||
=1.10.0 | ||
=1.10.0-a1 | ||
=1.10.0-b1 | ||
=1.10.0-rc1 | ||
=1.10.1 | ||
=1.10.2 | ||
=1.10.3 | ||
=1.10.4 | ||
=1.10.5 | ||
=1.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.