CVE-2015-0220

Publication date 13 January 2015

Last updated 24 July 2024


Ubuntu priority

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL.

Status

Package Ubuntu Release Status
python-django 14.10 utopic
Fixed 1.6.6-1ubuntu2.1
14.04 LTS trusty
Fixed 1.6.1-2ubuntu0.6
12.04 LTS precise
Fixed 1.3.1-4ubuntu1.13
10.04 LTS lucid
Fixed 1.1.1-2ubuntu1.14

References

Related Ubuntu Security Notices (USN)

    • USN-2469-1
    • Django vulnerabilities
    • 13 January 2015

Other references