6.1

CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

Data is provided by the National Vulnerability Database (NVD)
DjangoprojectDjango Version1.8.0
DjangoprojectDjango Version1.8.0 Updatea1
DjangoprojectDjango Version1.8.0 Updateb1
DjangoprojectDjango Version1.8.0 Updateb2
DjangoprojectDjango Version1.8.0 Updatec1
DjangoprojectDjango Version1.8.1
DjangoprojectDjango Version1.8.2
DjangoprojectDjango Version1.8.3
DjangoprojectDjango Version1.8.4
DjangoprojectDjango Version1.8.5
DjangoprojectDjango Version1.8.6
DjangoprojectDjango Version1.8.7
DjangoprojectDjango Version1.8.8
DjangoprojectDjango Version1.8.9
DjangoprojectDjango Version1.8.10
DjangoprojectDjango Version1.8.11
DjangoprojectDjango Version1.8.12
DjangoprojectDjango Version1.8.13
DjangoprojectDjango Version1.8.14
DjangoprojectDjango Version1.8.15
DjangoprojectDjango Version1.8.16
DjangoprojectDjango Version1.8.17
DjangoprojectDjango Version1.9
DjangoprojectDjango Version1.9 Updatea1
DjangoprojectDjango Version1.9 Updateb1
DjangoprojectDjango Version1.9 Updaterc1
DjangoprojectDjango Version1.9 Updaterc2
DjangoprojectDjango Version1.9.1
DjangoprojectDjango Version1.9.2
DjangoprojectDjango Version1.9.3
DjangoprojectDjango Version1.9.4
DjangoprojectDjango Version1.9.5
DjangoprojectDjango Version1.9.6
DjangoprojectDjango Version1.9.7
DjangoprojectDjango Version1.9.8
DjangoprojectDjango Version1.9.9
DjangoprojectDjango Version1.9.10
DjangoprojectDjango Version1.9.11
DjangoprojectDjango Version1.9.12
DjangoprojectDjango Version1.10.0
DjangoprojectDjango Version1.10.0 Updatea1
DjangoprojectDjango Version1.10.0 Updateb1
DjangoprojectDjango Version1.10.0 Updaterc1
DjangoprojectDjango Version1.10.1
DjangoprojectDjango Version1.10.2
DjangoprojectDjango Version1.10.3
DjangoprojectDjango Version1.10.4
DjangoprojectDjango Version1.10.5
DjangoprojectDjango Version1.10.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.75% 0.721
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.