Cross-site scripting in Django - CVE-2017-7233
Published: June 16, 2017
Vulnerability details
The disclosed vulnerability allows a remote attacker to redirect website visitors to external websites and perform cross-site scripting (XSS) attacks.
The vulnerability is caused by incorrect filtration of input data. A remote attacker can trick the victim to follow a specially crafted link, redirect the victim on potentially dangerous website and execute arbitrary HTML and script code in victim’s browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Arch Linux
Fedora
Ubuntu
py-django (Alpine package)
python-django (Red Hat package)
python-django16
python-django
Red Hat OpenStack
How to mitigate CVE-2017-7233
python-django (Red Hat package) - update to 1.6.11-7.el7ost
python-django16 - update to 1.6.11.7-5.el7
python-django - addressed in versions 1.9.13-1.fc25, 1.10.7-1.fc26, 1.11.13-2.el7, 1.11.13-4.el7
External References
Related Security Bulletins
- Two vulnerabilities in Django
- Arch Linux update for python-django
- Arch Linux update for python2-django
- Ubuntu update for Django
- Red Hat update for python-django
- Red Hat update for python-django
- Red Hat update for python-django
- Red Hat update for python-django
- Red Hat update for python-django
- Cross-site scripting in py-django (Alpine package)
- Fedora 26 update for python-django
- Fedora 25 update for python-django
- Fedora EPEL 7 update for python-django
- Fedora EPEL 7 update for python-django, python-django16
- Red Hat Enterprise Linux OpenStack Platform 6 update for python-django