[3.7] py-django: Open redirect possibility in CommonMiddleware (CVE-2018-14574)
If the django.middleware.common.CommonMiddleware and the APPEND_SLASH
setting are both enabled, and if the project
has a URL pattern that accepts any path ending in a slash (many content
management systems have such a pattern), then a request to
a maliciously crafted URL of that site could lead to a redirect to
another site, enabling phishing and other attacks.
Fixed In Version:
Django 1.11.15 and Django 2.0.8
References:
https://www.djangoproject.com/weblog/2018/aug/01/security-releases/
http://openwall.com/lists/oss-security/2018/08/01/2
Patch:
https://github.com/django/django/commit/d6eaee092709aad477a9894598496c6deec532ff
(from redmine: issue id 9176, created on 2018-08-02, closed on 2018-08-07)
- Relations:
- copied_to #9173 (closed)
- parent #9173 (closed)
- Changesets:
- Revision 8398d670 by Natanael Copa on 2018-08-06T15:33:38Z:
main/py-django: security upgrade to 1.11.15 (CVE-2018-14574)
fixes #9176