MGASA-2013-0256
Dashboard / Vulnerabilities / MGASA-2013-0256
Summary: Updated python-django packages fix CVE-2013-4249
Details: Updated python-django package fixes security vulnerability: The is_safe_url() function has been modified to properly recognize and reject URLs which specify a scheme other than HTTP or HTTPS, to prevent cross-site scripting attacks through redirecting to other schemes, such as javascript. (CVE-2013-4249).
References: https://advisories.mageia.org/MGASA-2013-0256.html, https://www.djangoproject.com/weblog/2013/aug/13/security-releases-issued, https://bugs.mageia.org/show_bug.cgi?id=10996
Affected packages
Package
Name: python-django
Purl: pkg:rpm/mageia/python-django?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.3.7-1.1.mga2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
