django: missing URL validation by AdminURLFieldWidget leads to generation of clickable unsafe JavaScript link causing cross site scripting
Published Jun 3, 2019
5.3
MEDIUMCVSS 4.0
EPSS 2.40%
Description
An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.
Affected products
No data.
- ≥ 1.11 · < 1.11.21
- ≥ 2.1 · < 2.1.9
- ≥ 2.2 · < 2.2.2
No data.
Red Hat Ceph Storage 2
python-django
Not affected
Red Hat Ceph Storage 3
python-django
Not affected
Red Hat Certification for Red Hat Enterprise Linux 7
python-django
Not affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
python-django
Not affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools
python-django
Not affected
Red Hat OpenStack Platform 10 (Newton)
python-django
Not affected
Red Hat OpenStack Platform 13 (Queens)
python-django
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
python-django
Affected
Red Hat OpenStack Platform 15 (Stein)
python-django
Not affected
Red Hat OpenStack Platform 8 (Liberty)
python-django
Not affected
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
python-django
Not affected
Red Hat OpenStack Platform 9 (Mitaka)
python-django
Not affected
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
python-django
Not affected
Red Hat Satellite 6
python-django
Not affected
Red Hat Storage 3
python-django
Will not fix
Red Hat Update Infrastructure 3 for Cloud Providers
python-django
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | python-django | Not affected | n/a |
| Red Hat Ceph Storage 3 | python-django | Not affected | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 7 | python-django | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-django | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-django | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | python-django | Affected | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | python-django | Not affected | n/a |
| Red Hat Satellite 6 | python-django | Not affected | n/a |
| Red Hat Storage 3 | python-django | Will not fix | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | python-django | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
* This issue affects the version of python-django as shipped with Red Hat Gluster Storage 3 as it contains the vulnerable code. * This issue does not affect Red Hat Satellite 6, versions 6.3, 6.4 and 6.5, because its django component only returns content-type as JSON, which does not lead to cross site scripting. * This issue does not affect Red Hat Update Infrastructure 3 because it does not use any of the Widgets provided by python-django, including AdminURLFieldWidget. * This issue does not affect redhat-certification because it does not use AdminURLFieldWidget from python-django package.
References (32)
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html vendor-advisoryx_refsource_SUSE
- http://www.openwall.com/lists/oss-security/2019/06/03/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108559 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2019-12308 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1715915 Issue Tracking
- https://docs.djangoproject.com/en/2.1/releases/2.1.9/
- https://docs.djangoproject.com/en/2.2/releases/1.11.21/
- https://docs.djangoproject.com/en/2.2/releases/2.2.2/
- https://docs.djangoproject.com/en/dev/releases/1.11.21 x_refsource_CONFIRMVendor Advisory
- https://docs.djangoproject.com/en/dev/releases/2.1.9 x_refsource_CONFIRMVendor Advisory
- https://docs.djangoproject.com/en/dev/releases/2.2.2 x_refsource_CONFIRMVendor Advisory
- https://docs.djangoproject.com/en/dev/releases/security x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0043 Advisory
- https://github.com/advisories/GHSA-7rp2-fm2h-wchj Advisory
- https://github.com/django/django/commit/09186a13d975de6d049f8b3e05484f66b01ece62
- https://github.com/django/django/commit/afddabf8428ddc89a332f7a78d0d21eaf2b5a673
- https://github.com/django/django/commit/c238701859a52d584f349cce15d56c8e8137c52b
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2019-79.yaml
- https://groups.google.com/forum/#!topic/django-announce/GEbHU7YoVz8
- https://groups.google.com/forum/#%21topic/django-announce/GEbHU7YoVz8 x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2019/06/msg00001.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2019/07/msg00001.html mailing-listx_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/USYRARSYB7PE3S2ZQO7PZNWMH7RPGL5G/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/USYRARSYB7PE3S2ZQO7PZNWMH7RPGL5G
- https://nvd.nist.gov/vuln/detail/CVE-2019-12308
- https://seclists.org/bugtraq/2019/Jul/10 mailing-listx_refsource_BUGTRAQ
- https://security.gentoo.org/glsa/202004-17 vendor-advisoryx_refsource_GENTOO
- https://usn.ubuntu.com/4043-1 vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-12308
- https://www.debian.org/security/2019/dsa-4476 vendor-advisoryx_refsource_DEBIAN
- https://www.djangoproject.com/weblog/2019/jun/03/security-releases x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.