CVE-2021-46898
Summary
| CVE | CVE-2021-46898 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-22 19:15:00 UTC |
| Updated | 2023-10-30 15:56:00 UTC |
| Description | views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Comparing 2.15.1...2.15.2 · sehmaschine/django-grappelli · GitHub |
MISC |
github.com |
|
| Update switch.py by ksg97031 · Pull Request #976 · sehmaschine/django-grappelli · GitHub |
MISC |
github.com |
|
| Update switch.py · sehmaschine/django-grappelli@4ca94bc · GitHub |
MISC |
github.com |
|
| Open redirect · Issue #975 · sehmaschine/django-grappelli · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995701 Python (Pip) Security Update for django-grappelli (GHSA-9x43-5qcq-h79q)