Cross-site scripting in Django - CVE-2016-2512
Published: December 21, 2016 / Updated: May 16, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The weakness exists in the utils.http.is_safe_url function due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Debian Linux
Fedora
Ubuntu
py-django (Alpine package)
python-django (Red Hat package)
python-django
Red Hat OpenStack
How to mitigate CVE-2016-2512
python-django (Red Hat package) - addressed in versions 1.6.11-5.el6ost, 1.6.11-5.el7ost
python-django - addressed in versions 1.6.11-5.el7, 1.8.10-1.fc22, 1.8.10-1.fc23, 1.8.11-1.fc22, 1.8.11-1.fc23
External References
Related Security Bulletins
- Multiple vulnerabilities in Django
- Ubuntu update for Django
- Ubuntu update for Django
- Ubuntu update for Django
- Debian update for python-django
- Red Hat update for python-django
- Red Hat update for python-django
- Cross-site scripting in py-django (Alpine package)
- Fedora 23 update for python-django
- Fedora 22 update for python-django
- Fedora EPEL 7 update for python-django
- Fedora 23 update for python-django
- Fedora 22 update for python-django
- Red Hat Enterprise Linux OpenStack Platform 5 update for python-django
- Red Hat Enterprise Linux OpenStack Platform 6 update for python-django
- Red Hat Enterprise Linux OpenStack Platform 5 update for python-django