PT-2019-1680 · Django Software Foundation+2 · Django+2
CVE-2019-3498
·
Publicado
2019-01-04
·
Atualizado
2026-07-14
CVSS v4.0
7.1
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Django versions 1.11.x through 1.11.17
Django versions 2.0.x through 2.0.9
Django versions 2.1.x through 2.1.4
Description
The issue is related to insufficient neutralization of special elements in output used by a downstream component. This can lead to content spoofing in a 404 error page if a user fails to recognize that a crafted URL has malicious content. The
django.views.defaults.page not found() function is specifically affected.Recommendations
For Django versions 1.11.x through 1.11.17, update to version 1.11.18 or later.
For Django versions 2.0.x through 2.0.9, update to version 2.0.10 or later.
For Django versions 2.1.x through 2.1.4, update to version 2.1.5 or later.
Correção
DoS
Special Elements Injection
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Django
Ubuntu