CVE-2019-3498
09.01.2019, 23:29
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.
Vendor | Product | Version |
---|---|---|
djangoproject | django | 1.11 ≤ 𝑥 < 1.11.18 |
djangoproject | django | 2.0 ≤ 𝑥 < 2.0.10 |
djangoproject | django | 2.1 ≤ 𝑥 < 2.1.5 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References