PYSEC-2012-7

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2012-7.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2012-7
Aliases
Published
2012-11-18T23:55:00Z
Modified
2026-06-10T17:00:53.800785285Z
Summary
[none]
Details

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

References

Affected packages

PyPI / django

Package

Affected ranges

Type
GIT
Repo
https://github.com/django/django
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Type
ECOSYSTEM
Events
Introduced
1.3
Fixed
1.3.4
Introduced
1.4
Fixed
1.4.2

Affected versions

1.*
1.0
1.1
1.2
1.2.1
1.3
1.3.1
1.3.2
1.3.3
1.4
1.4.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2012-7.yaml"