Oval Definition:oval:org.opensuse.security:def:20123442
Revision Date:2013-08-14Version:1
Title:CVE-2012-3442
Description:

The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2012-3442
Platform(s):openSUSE 12.1
openSUSE 12.1 Update
Product(s):
Definition Synopsis
  • Release Information
  • python-django-1.3.2-3.4.1 is installed
  • OR python-django-1.3.2-3.4.1 is installed
  • BACK