Bug 1031451 - (CVE-2017-7234) VUL-1: CVE-2017-7234: python-django: Open redirect vulnerability in django.views.static.serve()
(CVE-2017-7234)
VUL-1: CVE-2017-7234: python-django: Open redirect vulnerability in django.vi...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/182407/
CVSSv2:SUSE:CVE-2017-7234:4.0:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-03-29 08:16 UTC by Andreas Stieger
Modified: 2020-06-17 02:13 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2017-03-29 08:16:05 UTC
EMBARGOED via pre-notification.
CRD: 2017-04-04 14:00 UTC

CVE-2017-7234: Open redirect vulnerability in django.views.static.serve()
=========================================================================

A maliciously crafted URL to a Django site using the serve() view could
redirect to any other domain. The view no longer does any redirects as
they don't provide any known, useful functionality.

Note, however, that this view has always carried a warning that it is
not hardened for production use and should be used only as a development
aid.

Affected versions
=================

* Django master development branch
* Django 1.11 (currently at release candidate status)
* Django 1.10
* Django 1.9
* Django 1.8
Comment 7 Andreas Stieger 2017-04-05 07:51:59 UTC
Public at https://www.djangoproject.com/weblog/2017/apr/04/security-releases/
Comment 8 Swamp Workflow Management 2018-03-22 10:10:23 UTC
This is an autogenerated message for OBS integration:
This bug (1031451) was mentioned in
https://build.opensuse.org/request/show/589964 42.3 / python-Django
Comment 9 Swamp Workflow Management 2018-03-23 21:30:19 UTC
This is an autogenerated message for OBS integration:
This bug (1031451) was mentioned in
https://build.opensuse.org/request/show/590768 42.3 / python3-Django
Comment 10 Swamp Workflow Management 2018-03-27 10:08:42 UTC
openSUSE-SU-2018:0824-1: An update that fixes 12 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1001374,1008047,1008050,1031450,1031451,1056284,1083304,1083305,967999,968000
CVE References: CVE-2016-2048,CVE-2016-2512,CVE-2016-2513,CVE-2016-6186,CVE-2016-7401,CVE-2016-9013,CVE-2016-9014,CVE-2017-12794,CVE-2017-7233,CVE-2017-7234,CVE-2018-7536,CVE-2018-7537
Sources used:
openSUSE Leap 42.3 (src):    python3-Django-1.8.19-5.3.1
Comment 11 Swamp Workflow Management 2018-03-27 10:11:09 UTC
openSUSE-SU-2018:0826-1: An update that fixes 12 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1001374,1008047,1008050,1031450,1031451,1056284,1083304,1083305,967999,968000
CVE References: CVE-2016-2048,CVE-2016-2512,CVE-2016-2513,CVE-2016-6186,CVE-2016-7401,CVE-2016-9013,CVE-2016-9014,CVE-2017-12794,CVE-2017-7233,CVE-2017-7234,CVE-2018-7536,CVE-2018-7537
Sources used:
openSUSE Leap 42.3 (src):    python-Django-1.8.19-6.4.1
Comment 12 Swamp Workflow Management 2018-04-18 10:12:50 UTC
SUSE-SU-2018:0973-1: An update that fixes 8 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1001374,1008047,1008050,1031450,1031451,1056284,1083304,1083305
CVE References: CVE-2016-7401,CVE-2016-9013,CVE-2016-9014,CVE-2017-12794,CVE-2017-7233,CVE-2017-7234,CVE-2018-7536,CVE-2018-7537
Sources used:
SUSE OpenStack Cloud 7 (src):    python-Django-1.8.19-3.4.1
Comment 13 Swamp Workflow Management 2018-04-27 19:10:05 UTC
SUSE-SU-2018:1102-1: An update that fixes 9 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1001374,1008047,1008050,1031450,1031451,1056284,1083304,1083305,967999
CVE References: CVE-2016-2512,CVE-2016-7401,CVE-2016-9013,CVE-2016-9014,CVE-2017-12794,CVE-2017-7233,CVE-2017-7234,CVE-2018-7536,CVE-2018-7537
Sources used:
SUSE OpenStack Cloud 6 (src):    python-Django-1.8.19-3.6.1
Comment 14 Marcus Meissner 2019-07-10 05:48:17 UTC
done