First published: Wed Aug 01 2018(Updated: )
Andreas Hug discovered that Django contained an open redirect in CommonMiddleware. A remote attacker could possibly use this issue to perform phishing attacks.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python-django | <1:1.11.11-1ubuntu1.1 | 1:1.11.11-1ubuntu1.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/python3-django | <1:1.11.11-1ubuntu1.1 | 1:1.11.11-1ubuntu1.1 |
Ubuntu OpenSSH Client | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Django vulnerability is USN-3726-1.
The Django vulnerability is an open redirect in CommonMiddleware that could be exploited by a remote attacker to perform phishing attacks.
The Django vulnerability affects Ubuntu versions 18.04 with python-django version 1:1.11.11-1ubuntu1.1 and python3-django version 1:1.11.11-1ubuntu1.1.
The Django vulnerability can be exploited by a remote attacker to perform phishing attacks using the open redirect in CommonMiddleware.
You can find more information about this Django vulnerability on the Ubuntu Security Notices website: [USN-3726-1](https://ubuntu.com/security/notices/USN-3726-1) and the corresponding CVE-2018-14574.