First published: Thu Jul 26 2018(Updated: )
`django.middleware.common.CommonMiddleware` in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Djangoproject Django | >=1.11<1.11.15 | |
Djangoproject Django | >=2.0<2.0.8 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =18.04 | |
redhat/Django | <2.1 | 2.1 |
redhat/Django | <2.0.8 | 2.0.8 |
redhat/Django | <1.11.15 | 1.11.15 |
pip/django | >=2.0<2.0.8 | 2.0.8 |
pip/django | >=1.11.0<1.11.15 | 1.11.15 |
pip/Django | >=1.11<1.11.15 | 1.11.15 |
debian/python-django | 2:2.2.28-1~deb11u2 3:3.2.19-1+deb12u1 3:4.2.16-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-14574.
The severity of CVE-2018-14574 is medium with a CVSS score of 6.1.
Django versions 1.11.x before 1.11.15 and 2.0.x before 2.0.8 are affected by CVE-2018-14574.
To fix the vulnerability CVE-2018-14574, upgrade Django to version 1.11.15 or 2.0.8.
You can find more information about CVE-2018-14574 on the NIST NVD website, Red Hat Errata, and GitHub Advisories.