6.1

CVE-2017-7234

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DjangoprojectDjango Version1.8.0
DjangoprojectDjango Version1.8.0 Updatea1
DjangoprojectDjango Version1.8.0 Updateb1
DjangoprojectDjango Version1.8.0 Updateb2
DjangoprojectDjango Version1.8.0 Updatec1
DjangoprojectDjango Version1.8.1
DjangoprojectDjango Version1.8.2
DjangoprojectDjango Version1.8.3
DjangoprojectDjango Version1.8.4
DjangoprojectDjango Version1.8.5
DjangoprojectDjango Version1.8.6
DjangoprojectDjango Version1.8.7
DjangoprojectDjango Version1.8.8
DjangoprojectDjango Version1.8.9
DjangoprojectDjango Version1.8.10
DjangoprojectDjango Version1.8.11
DjangoprojectDjango Version1.8.12
DjangoprojectDjango Version1.8.13
DjangoprojectDjango Version1.8.14
DjangoprojectDjango Version1.8.15
DjangoprojectDjango Version1.8.16
DjangoprojectDjango Version1.8.17
DjangoprojectDjango Version1.9
DjangoprojectDjango Version1.9 Updatea1
DjangoprojectDjango Version1.9 Updateb1
DjangoprojectDjango Version1.9 Updaterc1
DjangoprojectDjango Version1.9 Updaterc2
DjangoprojectDjango Version1.9.1
DjangoprojectDjango Version1.9.2
DjangoprojectDjango Version1.9.3
DjangoprojectDjango Version1.9.4
DjangoprojectDjango Version1.9.5
DjangoprojectDjango Version1.9.6
DjangoprojectDjango Version1.9.7
DjangoprojectDjango Version1.9.8
DjangoprojectDjango Version1.9.9
DjangoprojectDjango Version1.9.10
DjangoprojectDjango Version1.9.11
DjangoprojectDjango Version1.9.12
DjangoprojectDjango Version1.10.0
DjangoprojectDjango Version1.10.0 Updatea1
DjangoprojectDjango Version1.10.0 Updateb1
DjangoprojectDjango Version1.10.0 Updaterc1
DjangoprojectDjango Version1.10.1
DjangoprojectDjango Version1.10.2
DjangoprojectDjango Version1.10.3
DjangoprojectDjango Version1.10.4
DjangoprojectDjango Version1.10.5
DjangoprojectDjango Version1.10.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.612
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.