Oval Definition:oval:com.ubuntu.xenial:def:201772330000000
Revision Date:2017-04-04Version:1
Title:CVE-2017-7233 on Ubuntu 16.04 LTS (xenial) - medium.
Description:Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-7233
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND python-django package in xenial was vulnerable but has been fixed (note: '1.8.7-1ubuntu5.5').
  • BACK