Back

MEDIUM

Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

Published Jul 1, 2019

Description

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.

Affected products

Remediation

Red Hat statement

This issue does not affect any versions of python-django as shipped with Red Hat Update Infrastructure for Cloud Providers as the load balancer should not be configured to forward HTTP requests.

Weaknesses (2)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 1, 2019
Updated Aug 4, 2024
Reserved Jun 10, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 1, 2019
ENISA EUVD
Assigner mitre
Published Jul 1, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-0034 GHSA-6C7V-2F49-8H26