CVE-2017-7233
Summary
| CVE | CVE-2017-7233 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-04 17:59:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack. |
Risk And Classification
Primary CVSS: v3.0 6.1 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-601 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.1 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 5.8 | AV:N/AC:M/Au:N/C:P/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Djangoproject | Django | 1.10.0 | All | All | All |
| Application | Djangoproject | Django | 1.10.0 | a1 | All | All |
| Application | Djangoproject | Django | 1.10.0 | b1 | All | All |
| Application | Djangoproject | Django | 1.10.0 | rc1 | All | All |
| Application | Djangoproject | Django | 1.10.1 | All | All | All |
| Application | Djangoproject | Django | 1.10.2 | All | All | All |
| Application | Djangoproject | Django | 1.10.3 | All | All | All |
| Application | Djangoproject | Django | 1.10.4 | All | All | All |
| Application | Djangoproject | Django | 1.10.5 | All | All | All |
| Application | Djangoproject | Django | 1.10.6 | All | All | All |
| Application | Djangoproject | Django | 1.8.0 | All | All | All |
| Application | Djangoproject | Django | 1.8.0 | a1 | All | All |
| Application | Djangoproject | Django | 1.8.0 | b1 | All | All |
| Application | Djangoproject | Django | 1.8.0 | b2 | All | All |
| Application | Djangoproject | Django | 1.8.0 | c1 | All | All |
| Application | Djangoproject | Django | 1.8.1 | All | All | All |
| Application | Djangoproject | Django | 1.8.10 | All | All | All |
| Application | Djangoproject | Django | 1.8.11 | All | All | All |
| Application | Djangoproject | Django | 1.8.12 | All | All | All |
| Application | Djangoproject | Django | 1.8.13 | All | All | All |
| Application | Djangoproject | Django | 1.8.14 | All | All | All |
| Application | Djangoproject | Django | 1.8.15 | All | All | All |
| Application | Djangoproject | Django | 1.8.16 | All | All | All |
| Application | Djangoproject | Django | 1.8.17 | All | All | All |
| Application | Djangoproject | Django | 1.8.2 | All | All | All |
| Application | Djangoproject | Django | 1.8.3 | All | All | All |
| Application | Djangoproject | Django | 1.8.4 | All | All | All |
| Application | Djangoproject | Django | 1.8.5 | All | All | All |
| Application | Djangoproject | Django | 1.8.6 | All | All | All |
| Application | Djangoproject | Django | 1.8.7 | All | All | All |
| Application | Djangoproject | Django | 1.8.8 | All | All | All |
| Application | Djangoproject | Django | 1.8.9 | All | All | All |
| Application | Djangoproject | Django | 1.9 | All | All | All |
| Application | Djangoproject | Django | 1.9 | a1 | All | All |
| Application | Djangoproject | Django | 1.9 | b1 | All | All |
| Application | Djangoproject | Django | 1.9 | rc1 | All | All |
| Application | Djangoproject | Django | 1.9 | rc2 | All | All |
| Application | Djangoproject | Django | 1.9.1 | All | All | All |
| Application | Djangoproject | Django | 1.9.10 | All | All | All |
| Application | Djangoproject | Django | 1.9.11 | All | All | All |
| Application | Djangoproject | Django | 1.9.12 | All | All | All |
| Application | Djangoproject | Django | 1.9.2 | All | All | All |
| Application | Djangoproject | Django | 1.9.3 | All | All | All |
| Application | Djangoproject | Django | 1.9.4 | All | All | All |
| Application | Djangoproject | Django | 1.9.5 | All | All | All |
| Application | Djangoproject | Django | 1.9.6 | All | All | All |
| Application | Djangoproject | Django | 1.9.7 | All | All | All |
| Application | Djangoproject | Django | 1.9.8 | All | All | All |
| Application | Djangoproject | Django | 1.9.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Debian -- Security Information -- DSA-3835-1 python-django | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Django security releases issued: 1.10.7, 1.9.13, and 1.8.18 | Weblog | Django | af854a3a-2127-422b-91ae-364da2661108 | www.djangoproject.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Django 'django.contrib.auth.views.login()' Function Open Redirection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Django Input Validation Flaws Let Remote Users Conduct Cross-Site Scripting and Open Redirect Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.