Bugzilla – Bug 877993
VUL-0: CVE-2014-1418: python-django: Insecure redirects and cache poisoning
Last modified: 2015-02-19 10:32:45 UTC
Via oss-security Two issues were reported in python-django: - Caches may be allowed to store and serve private data (CVE-2014-1418) - Malformed URLs from user input incorrectly validated. Affected versions - master development branch - 1.7 - 1.6 - 1.5 - 1.4 References: https://bugzilla.redhat.com/show_bug.cgi?id=1097500 http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-1418.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-1418 https://www.djangoproject.com/weblog/2014/may/14/security-releases-issued/
The SWAMPID for this issue is 57432. This issue was rated as moderate. Please submit fixed packages until 2014-05-29. When done, please reassign the bug to security-team@suse.de. Patchinfo will be handled by security team.
Affected packages: SLE-11-SP3: python-django SLE-11-SP3-PRODUCTS: python-django SLE-11-SP3-CLOUD4: python-django
bugbot adjusting priority
Second issue (malformed URLs from user input incorrectly validated) received a CVE. https://bugzilla.novell.com/show_bug.cgi?id=878641
Reassigning to security team as fix was submitted.
Update released for: python-django Products: SUSE-CLOUD 3.0 (x86_64)
SUSE-SU-2014:0851-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 874950,874955,874956,877993,878641 CVE References: CVE-2014-0472,CVE-2014-0473,CVE-2014-0474,CVE-2014-1418,CVE-2014-3730 Sources used: SUSE Cloud 3 (src): python-django-1.5.8-0.7.1
Fix was released. Closing bug.
openSUSE-SU-2014:1132-1: An update that fixes 9 vulnerabilities is now available. Category: security (moderate) Bug References: 874950,874955,874956,877993,878641,893087,893088,893089,893090 CVE References: CVE-2014-0472,CVE-2014-0473,CVE-2014-0474,CVE-2014-0480,CVE-2014-0481,CVE-2014-0482,CVE-2014-0483,CVE-2014-1418,CVE-2014-3730 Sources used: openSUSE 13.1 (src): python-django-1.5.10-0.2.8.1 openSUSE 12.3 (src): python-django-1.4.15-2.12.1