PT-2019-2628 · Django Software Foundation+3 · Django+3
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Django versions 1.11 before 1.11.22
Django versions 2.1 before 2.1.10
Django versions 2.2 before 2.2.3
Description
An issue in Django causes incorrect behavior of
django.http.HttpRequest.scheme when a client uses HTTP, but the proxy connects to Django via HTTPS, and the SECURE PROXY SSL HEADER and SECURE SSL REDIRECT settings are used. This issue is related to errors in processing HTTP requests that are determined as HTTPS requests. The exploitation of this issue may allow a remote attacker to access protected information.Recommendations
For Django version 1.11 before 1.11.22, update to version 1.11.22 or later.
For Django version 2.1 before 2.1.10, update to version 2.1.10 or later.
For Django version 2.2 before 2.2.3, update to version 2.2.3 or later.
Fix
DoS
Cleartext Transmission of Sensitive Information
HTTP Request/Response Smuggling
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Django
Suse
Ubuntu