CVE-2014-0480
Publication date 26 August 2014
Last updated 24 July 2024
Ubuntu priority
The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | 14.04 LTS trusty |
Fixed 1.6.1-2ubuntu0.4
|
Patch details
Package | Patch details |
---|---|
python-django |
|
References
Related Ubuntu Security Notices (USN)
- USN-2347-1
- Django vulnerabilities
- 16 September 2014