← Back

CVE-2014-3730

nvd nist
Published: May 16, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."

Affected (43)

Show all products
1 product
Ubuntu Linux
1 product
Django
1 product
Opensuse
1 product
Debian Linux
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 10.04
Version 12.04
Version 12.10
Version 13.10
Version 14.04
Configuration B
12 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Version 1.4.10
Version 1.4.11
Version 1.4.12
Version 1.4.1
Version 1.4.2
Version 1.4.4
Version 1.4.5
Version 1.4.6
Version 1.4.7
Version 1.4.8
Version 1.4.9
Version 1.4
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Version 1.7 beta1
Version 1.7 beta2
Version 1.7 beta3
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 12.3
Version 13.1
Configuration E
9 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.6
Version 1.6 beta1
Version 1.6 beta2
Version 1.6 beta3
Version 1.6 beta4
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 7.0
Version 8.0
Configuration G
10 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5.4
Version 1.5.5
Version 1.5.6
Version 1.5.7
Version 1.5
Version 1.5 alpha
Version 1.5 beta

References (16)

Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.