A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the django.views.static.serve() view could redirect to any other domain, aka an open redirect vulnerability.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.13"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.14"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.16"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.17"
},
{
"introduced": "0"
},
{
"last_affected": "1.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.9-a1"
},
{
"introduced": "0"
},
{
"last_affected": "1.9-b1"
},
{
"introduced": "0"
},
{
"last_affected": "1.9-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "1.9-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.6"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0-a1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0-b1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0-b2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0-c1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.10.0-a1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.10.0-b1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.10.0-rc1"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7234.json"