QID 994933
Date Published: 2023-08-21
QID 994933: Python (Pip) Security Update for django (GHSA-vq3h-3q7v-9prw)
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\djangoproject.com."
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vq3h-3q7v-9prw for updates and patch information.
Vendor References
- GHSA-vq3h-3q7v-9prw -
github.com/advisories/GHSA-vq3h-3q7v-9prw
CVEs related to QID 994933
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vq3h-3q7v-9prw | django |
|