Back

HIGH

python-django: Content spoofing via URL path in default 404 page

Published Jan 9, 2019

Description

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.

Affected products

Remediation

Red Hat statement

This issue affects the versions of python-django as shipped with Red Hat Update Infrastructure 3. Even though the Red Hat Update Appliance ships python-django, the application is not accessible by default because of the firewall rules, thus this flaw cannot be used. However, it can be triggered on the Content Delivery Systems. Red Hat Satellite is not affected, since python-django is only used on Pulp API, which only returns JSON data.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 9, 2019
Updated Aug 4, 2024
Reserved Jan 1, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 7, 2019
GHSA-337X-4Q8G-PRC5