CVE-2019-3498
09.01.2019, 23:29
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.
| Vendor | Product | Version |
|---|---|---|
| djangoproject | django | 1.11 ≤ 𝑥 < 1.11.18 |
| djangoproject | django | 2.0 ≤ 𝑥 < 2.0.10 |
| djangoproject | django | 2.1 ≤ 𝑥 < 2.1.5 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References