MGASA-2013-0256

Source
https://advisories.mageia.org/MGASA-2013-0256.html
Import Source
https://advisories.mageia.org/MGASA-2013-0256.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0256
Related
Published
2013-08-22T18:13:04Z
Modified
2026-02-04T02:17:37.256340Z
Summary
Updated python-django packages fix CVE-2013-4249
Details

Updated python-django package fixes security vulnerability:

The issafeurl() function has been modified to properly recognize and reject URLs which specify a scheme other than HTTP or HTTPS, to prevent cross-site scripting attacks through redirecting to other schemes, such as javascript. (CVE-2013-4249).

References
Credits

Affected packages

Mageia:2 / python-django

Package

Name
python-django
Purl
pkg:rpm/mageia/python-django?arch=source&distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.7-1.1.mga2

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0256.json"

Mageia:3 / python-django

Package

Name
python-django
Purl
pkg:rpm/mageia/python-django?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.6-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0256.json"