Junglewise Threat Intelligence

CVE-2017-7233: PYSEC-2017-9 - Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on succes

CVE-2017-7233 · Severity: low · CVSS 3 · Published 2017-04-04

Technologies: Django (PyPI), Django. Vendors: PyPI, Django.

Executive brief

Django is a popular web framework used to build dynamic websites and applications. The framework includes a security function to prevent attackers from redirecting users to malicious sites, but a flaw in this function failed to block certain numeric URLs, allowing attackers to redirect users to external sites or inject malicious scripts. This could lead to phishing attacks, credential theft, or defacement of web pages.

Technical details

The vulnerability exists in Django's is_safe_url() validation function, which is used to check whether redirect URLs are safe before sending users to them. The function incorrectly classified certain numeric URLs as safe, violating the CWE-601 (Open Redirect) vulnerability class. An attacker can craft a numeric redirect URL to bypass the validation, enabling open redirect attacks. Additionally, if developers embed these URLs directly in HTML links without additional sanitization, reflected XSS is possible. No authentication is required; the attack leverages user interaction (clicking a malicious link). Patches were released in Django 1.8.18, 1.9.13, and 1.10.7.

Affected products

  • Django Django 1.8 before 1.8.18, 1.9 before 1.9.13, 1.10 before 1.10.7

Timeline

  • 2017-04-04: disclosed
  • 2017-04-04: patched

References

Related threats