QID 994930

Date Published: 2023-08-21

QID 994930: Python (Pip) Security Update for django (GHSA-f7cm-ccfp-3q4r)

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Refer to Github security advisory GHSA-f7cm-ccfp-3q4r for updates and patch information.
    Vendor References

    CVEs related to QID 994930

    Software Advisories
    Advisory ID Software Component Link
    GHSA-f7cm-ccfp-3q4r django URL Logo github.com/advisories/GHSA-f7cm-ccfp-3q4r