CVE-2014-3730
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as…
Does this matter?
Lower severity and a low EPSS score (3.15%). Track it; it rarely justifies an emergency change on its own.
Description
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.15% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- canonical/ubuntu linux · djangoproject/django · opensuse/opensuse · debian/debian linux
- Source
- security@debian.org
References
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.htmlThird Party Advisory
- http://secunia.com/advisories/61281
- http://ubuntu.com/usn/usn-2212-1Third Party Advisory
- http://www.debian.org/security/2014/dsa-2934Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/05/14/10Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/05/15/3Third Party Advisory
- http://www.securityfocus.com/bid/67410Third Party Advisory, VDB Entry
- https://www.djangoproject.com/weblog/2014/may/14/security-releases-issued/Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.htmlThird Party Advisory
- http://secunia.com/advisories/61281
- http://ubuntu.com/usn/usn-2212-1Third Party Advisory
- http://www.debian.org/security/2014/dsa-2934Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/05/14/10Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/05/15/3Third Party Advisory
- http://www.securityfocus.com/bid/67410Third Party Advisory, VDB Entry
- https://www.djangoproject.com/weblog/2014/may/14/security-releases-issued/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.