Back

MEDIUM

django: possible XSS via admin ForeignKeyRawIdWidget

Published Jun 3, 2020

Description

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

Affected products

Remediation

Red Hat statement

The following products ship the flawed code, however they do not make use of ForeignKeyRawIdWidget and are therefore not vulnerable to this flaw: * Red Hat Satellite 6 * Red Hat Update Infrastructure 3 * Red Hat OpenStack Platform 13, 15, & 16 * Red Hat Gluster Storage 3 The version of python-django shipped with Red Hat Ceph Storage(RHCS) was used with calamari and graphite which are no more supported, hence the django package will not be fixed for RHCS.

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 3, 2020
Updated Aug 4, 2024
Reserved May 26, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 3, 2020
GHSA-2M34-JCJV-45XF