Django open redirect
Moderate severity
GitHub Reviewed
Published
Jan 4, 2019
to the GitHub Advisory Database
•
Updated Sep 18, 2024
Package
Affected versions
>= 1.10, < 1.10.7
>= 1.9, < 1.9.13
>= 1.8, < 1.8.18
Patched versions
1.10.7
1.9.13
1.8.18
Description
Published to the GitHub Advisory Database
Jan 4, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 18, 2024
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the
django.views.static.serve()
view could redirect to any other domain, aka an open redirect vulnerability.References