CVE-2019-12308
Summary
| CVE | CVE-2019-12308 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-03 17:29:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Archive of security issues | Django documentation | Django |
MISC |
docs.djangoproject.com |
Vendor Advisory |
| [SECURITY] Fedora 30 Update: python-django-2.1.9-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-4476-1 python-django |
DEBIAN |
www.debian.org |
|
| oss-security - Django: CVE-2019-12308 AdminURLFieldWidget XSS (plus patched bundled
jQuery for CVE-2019-11358) |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1839-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [SECURITY] [DLA 1842-1] python-django security update |
MLIST |
lists.debian.org |
|
| Django 2.1.9 release notes | Django documentation | Django |
CONFIRM |
docs.djangoproject.com |
Vendor Advisory |
| Bugtraq: [SECURITY] [DSA 4476-1] python-django security update |
BUGTRAQ |
seclists.org |
|
| Django 1.11.21 release notes | Django documentation | Django |
CONFIRM |
docs.djangoproject.com |
Vendor Advisory |
| Google Groups |
MISC |
groups.google.com |
Mailing List, Vendor Advisory |
| USN-4043-1: Django vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| Django CVE-2019-12308 Cross Site Scripting Vulnerability |
BID |
www.securityfocus.com |
|
| [SECURITY] [DLA 1814-1] python-django security update |
MLIST |
lists.debian.org |
|
| Google Groups |
|
groups.google.com |
|
| [SECURITY] Fedora 30 Update: python-django-2.1.9-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Django: Multiple vulnerabilities (GLSA 202004-17) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Django security releases issued: 2.2.2, 2.1.9 and 1.11.21 | Weblog | Django |
CONFIRM |
www.djangoproject.com |
Vendor Advisory |
| [security-announce] openSUSE-SU-2019:1872-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| Django 2.2.2 release notes | Django documentation | Django |
CONFIRM |
docs.djangoproject.com |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500573 Alpine Linux Security Update for py3-django
- 981744 Python (pip) Security Update for django (GHSA-7rp2-fm2h-wchj)