CVE-2017-7233
Last modified
CVE-2017-7233 is a vulnerability of currently unknown severity. Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. EPSS estimates a 2.38% chance of exploitation in the next 30 days.
Description
Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Djangoproject | Django | 1.8.0 |
| Djangoproject | Django | 1.8.1 |
| Djangoproject | Django | 1.8.2 |
| Djangoproject | Django | 1.8.3 |
| Djangoproject | Django | 1.8.4 |
| Djangoproject | Django | 1.8.5 |
| Djangoproject | Django | 1.8.6 |
| Djangoproject | Django | 1.8.7 |
| Djangoproject | Django | 1.8.8 |
| Djangoproject | Django | 1.8.9 |
| Djangoproject | Django | 1.8.10 |
| Djangoproject | Django | 1.8.11 |
| Djangoproject | Django | 1.8.12 |
| Djangoproject | Django | 1.8.13 |
| Djangoproject | Django | 1.8.14 |
| Djangoproject | Django | 1.8.15 |
| Djangoproject | Django | 1.8.16 |
| Djangoproject | Django | 1.8.17 |
| Djangoproject | Django | 1.9 |
| Djangoproject | Django | 1.9.1 |
| Djangoproject | Django | 1.9.2 |
| Djangoproject | Django | 1.9.3 |
| Djangoproject | Django | 1.9.4 |
| Djangoproject | Django | 1.9.5 |
| Djangoproject | Django | 1.9.6 |
| Djangoproject | Django | 1.9.7 |
| Djangoproject | Django | 1.9.8 |
| Djangoproject | Django | 1.9.9 |
| Djangoproject | Django | 1.9.10 |
| Djangoproject | Django | 1.9.11 |
| Djangoproject | Django | 1.9.12 |
| Djangoproject | Django | 1.10.0 |
| Djangoproject | Django | 1.10.1 |
| Djangoproject | Django | 1.10.2 |
| Djangoproject | Django | 1.10.3 |
| Djangoproject | Django | 1.10.4 |
| Djangoproject | Django | 1.10.5 |
| Djangoproject | Django | 1.10.6 |
References
- http://www.securityfocus.com/bid/97406Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/97406Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7233?
How severe is CVE-2017-7233?
How do I fix CVE-2017-7233?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7226The pe_ILF_object_p function in the Binary File Descriptor (…
- CVE-2017-7227GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap…
- CVE-2017-7228An issue (known as XSA-212) was discovered in Xen, with fixe…
- CVE-2017-7229PGP/MIME encrypted messages injected into a Vaultive O365 (b…
- CVE-2017-7230A buffer overflow vulnerability in Disk Sorter Enterprise 9.…
- CVE-2017-7231pngdefry through 2017-03-22 is prone to a heap-based buffer-…
- CVE-2017-7234A maliciously crafted URL to a Django (1.10 before 1.10.7, 1…
- CVE-2017-7235An issue was discovered in cloudflare-scrape 1.6.6 through 1…
- CVE-2017-7236SQL injection vulnerability in NetApp OnCommand Unified Mana…
- CVE-2017-7237The Spiceworks TFTP Server, as distributed with Spiceworks I…
- CVE-2017-7239Ninka before 1.3.2 might allow remote attackers to obtain se…
- CVE-2017-7240An issue was discovered on Miele Professional PST10 devices.…
Are you affected by CVE-2017-7233?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
