CVE-2015-2317
25.03.2015, 14:59
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.
Vendor | Product | Version |
---|---|---|
debian | debian_linux | 7.0 |
opensuse | opensuse | 13.2 |
djangoproject | django | 𝑥 ≤ 1.4.19 |
djangoproject | django | 1.5 |
djangoproject | django | 1.5:alpha |
djangoproject | django | 1.5:beta |
djangoproject | django | 1.5.1 |
djangoproject | django | 1.5.2 |
djangoproject | django | 1.5.3 |
djangoproject | django | 1.5.4 |
djangoproject | django | 1.5.5 |
djangoproject | django | 1.5.6 |
djangoproject | django | 1.5.7 |
djangoproject | django | 1.5.8 |
djangoproject | django | 1.5.9 |
djangoproject | django | 1.5.10 |
djangoproject | django | 1.5.11 |
djangoproject | django | 1.5.12 |
djangoproject | django | 1.6 |
djangoproject | django | 1.6:beta1 |
djangoproject | django | 1.6:beta2 |
djangoproject | django | 1.6:beta3 |
djangoproject | django | 1.6:beta4 |
djangoproject | django | 1.6.1 |
djangoproject | django | 1.6.2 |
djangoproject | django | 1.6.3 |
djangoproject | django | 1.6.4 |
djangoproject | django | 1.6.5 |
djangoproject | django | 1.6.6 |
djangoproject | django | 1.6.7 |
djangoproject | django | 1.6.8 |
djangoproject | django | 1.6.9 |
djangoproject | django | 1.6.10 |
djangoproject | django | 1.7:beta1 |
djangoproject | django | 1.7:beta2 |
djangoproject | django | 1.7:beta3 |
djangoproject | django | 1.7:beta4 |
djangoproject | django | 1.7:rc1 |
djangoproject | django | 1.7:rc2 |
djangoproject | django | 1.7:rc3 |
djangoproject | django | 1.7.1 |
djangoproject | django | 1.7.2 |
djangoproject | django | 1.7.3 |
djangoproject | django | 1.7.4 |
djangoproject | django | 1.7.5 |
djangoproject | django | 1.7.6 |
djangoproject | django | 1.8.0 |
oracle | solaris | 11.2 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 14.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References