Server side cross-site scripting In django
Description
Django Allows Redirect via Data URL
The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 1.3.2, 1.4.1 | ||
debian 13 | 1.4.1-1 | ||
debian 12 | 1.4.1-1 | ||
debian 14 | 1.4.1-1 | ||
debian 11 | 1.4.1-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.