CVE-2019-12781
01.07.2019, 14:15
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.Enginsight
Vendor | Product | Version |
---|---|---|
djangoproject | django | 1.11 ≤ 𝑥 < 1.11.22 |
djangoproject | django | 2.1 ≤ 𝑥 < 2.1.10 |
djangoproject | django | 2.2 ≤ 𝑥 < 2.2.3 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
canonical | ubuntu_linux | 19.04 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python-django |
|
Common Weakness Enumeration
References