Description
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-885-1 | python-django security update |
Debian DSA |
DSA-3835-1 | python-django security update |
EUVD |
EUVD-2017-0024 | A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability. |
Github GHSA |
GHSA-h4hv-m4h4-mhwg | Django open redirect |
Ubuntu USN |
USN-3254-1 | Django vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:56:36.057Z
Reserved: 2017-03-22T00:00:00.000Z
Link: CVE-2017-7234
No data.
Status : Modified
Published: 2017-04-04T17:59:00.303
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-7234
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN