Back

MEDIUM

django: missing URL validation by AdminURLFieldWidget leads to generation of clickable unsafe JavaScript link causing cross site scripting

Published Jun 3, 2019

Description

An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.

Affected products

Remediation

Red Hat statement

* This issue affects the version of python-django as shipped with Red Hat Gluster Storage 3 as it contains the vulnerable code. * This issue does not affect Red Hat Satellite 6, versions 6.3, 6.4 and 6.5, because its django component only returns content-type as JSON, which does not lead to cross site scripting. * This issue does not affect Red Hat Update Infrastructure 3 because it does not use any of the Widgets provided by python-django, including AdminURLFieldWidget. * This issue does not affect redhat-certification because it does not use AdminURLFieldWidget from python-django package.

References (32)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 3, 2019
Updated Aug 4, 2024
Reserved May 23, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 3, 2019
ENISA EUVD
Assigner mitre
Published Jun 3, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-0043 GHSA-7RP2-FM2H-WCHJ