VulnerabilityModified
CVE-2019-12781
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3.
MEDIUM 5.3EPSS 1.71%
Does this matter?
Lower severity and a low EPSS score (1.71%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- djangoproject/django · canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html
- http://www.openwall.com/lists/oss-security/2019/07/01/3Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/109018Third Party Advisory
- https://docs.djangoproject.com/en/dev/releases/security/Patch, Vendor Advisory
- https://groups.google.com/forum/#%21topic/django-announce/Is4kLY9ZcZQ
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VXXWIOQGXOB7JCGJ3CVUW673LDHKEYL/
- https://seclists.org/bugtraq/2019/Jul/10Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190705-0002/Third Party Advisory
- https://usn.ubuntu.com/4043-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4476Third Party Advisory
- https://www.djangoproject.com/weblog/2019/jul/01/security-releases/Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html
- http://www.openwall.com/lists/oss-security/2019/07/01/3Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/109018Third Party Advisory
- https://docs.djangoproject.com/en/dev/releases/security/Patch, Vendor Advisory
- https://groups.google.com/forum/#%21topic/django-announce/Is4kLY9ZcZQ
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VXXWIOQGXOB7JCGJ3CVUW673LDHKEYL/
- https://seclists.org/bugtraq/2019/Jul/10Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190705-0002/Third Party Advisory
- https://usn.ubuntu.com/4043-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4476Third Party Advisory
- https://www.djangoproject.com/weblog/2019/jul/01/security-releases/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.