{"schema_version":"1.7.3","id":"GHSA-37hp-765x-j95x","published":"2019-01-04T17:50:26Z","modified":"2024-09-18T16:25:30.395015Z","aliases":["CVE-2017-7233","PYSEC-2017-9"],"summary":"Django open redirect and possible XSS attack via user-supplied numeric redirect URLs","details":"Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an \"on success\" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs \"safe\" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.","affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.10a1"},{"fixed":"1.10.7"}]}],"versions":["1.10","1.10.1","1.10.2","1.10.3","1.10.4","1.10.5","1.10.6","1.10a1","1.10b1","1.10rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-37hp-765x-j95x/GHSA-37hp-765x-j95x.json"}},{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.9a1"},{"fixed":"1.9.13"}]}],"versions":["1.9","1.9.1","1.9.10","1.9.11","1.9.12","1.9.2","1.9.3","1.9.4","1.9.5","1.9.6","1.9.7","1.9.8","1.9.9","1.9a1","1.9b1","1.9rc1","1.9rc2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-37hp-765x-j95x/GHSA-37hp-765x-j95x.json"}},{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.8a1"},{"fixed":"1.8.18"}]}],"versions":["1.8","1.8.1","1.8.10","1.8.11","1.8.12","1.8.13","1.8.14","1.8.15","1.8.16","1.8.17","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.8.8","1.8.9","1.8a1","1.8b1","1.8b2","1.8c1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-37hp-765x-j95x/GHSA-37hp-765x-j95x.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7233"},{"type":"WEB","url":"https://github.com/django/django/commit/254326cb3682389f55f886804d2c43f7b9f23e4f"},{"type":"WEB","url":"https://github.com/django/django/commit/8339277518c7d8ec280070a780915304654e3b66"},{"type":"WEB","url":"https://github.com/django/django/commit/f824655bc2c50b19d2f202d7640785caabc82787"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2017:1445"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2017:1451"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2017:1462"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2017:1470"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2017:1596"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2017:3093"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2927"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-37hp-765x-j95x"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2017-9.yaml"},{"type":"WEB","url":"https://www.djangoproject.com/weblog/2017/apr/04/security-releases"},{"type":"WEB","url":"http://www.debian.org/security/2017/dsa-3835"}],"database_specific":{"cwe_ids":["CWE-601"],"github_reviewed":true,"github_reviewed_at":"2020-06-16T20:54:21Z","nvd_published_at":null,"severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}