QID 995701
Date Published: 2023-10-25
QID 995701: Python (Pip) Security Update for django-grappelli (GHSA-9x43-5qcq-h79q)
views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9x43-5qcq-h79q for updates and patch information.
Vendor References
- GHSA-9x43-5qcq-h79q -
github.com/advisories/GHSA-9x43-5qcq-h79q
CVEs related to QID 995701
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9x43-5qcq-h79q | django-grappelli |
|