django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://www.djangoproject.com/weblog/2018/aug/01/security-releases/ | patch vendor advisory |
https://usn.ubuntu.com/3726-1/ | third party advisory vendor advisory |
https://www.debian.org/security/2018/dsa-4264 | third party advisory vendor advisory |
http://www.securitytracker.com/id/1041403 | third party advisory vdb entry |
https://access.redhat.com/errata/RHSA-2019:0265 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/104970 | third party advisory vdb entry |