2024-06-28 13:17:52 +00:00

140 lines
5.6 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20171458",
"Version": "oval:org.altlinux.errata:def:20171458",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-1458: package `python-module-django` update to version 1.8.18-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-1458",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-1458",
"Source": "ALTPU"
},
{
"RefID": "CVE-2017-7233",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-7233",
"Source": "CVE"
},
{
"RefID": "CVE-2017-7234",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-7234",
"Source": "CVE"
}
],
"Description": "This update upgrades python-module-django to version 1.8.18-alt1. \nSecurity Fix(es):\n\n * CVE-2017-7233: Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an \"on success\" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs \"safe\" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.\n\n * CVE-2017-7234: A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-04-12"
},
"Updated": {
"Date": "2017-04-12"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2017-7233",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-601",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-7233",
"Impact": "Low",
"Public": "20170404"
},
{
"ID": "CVE-2017-7234",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-601",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-7234",
"Impact": "Low",
"Public": "20170404"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20171458001",
"Comment": "python-module-django is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458002",
"Comment": "python-module-django-dbbackend-mysql is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458003",
"Comment": "python-module-django-dbbackend-psycopg2 is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458004",
"Comment": "python-module-django-dbbackend-sqlite3 is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458005",
"Comment": "python-module-django-doc is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458006",
"Comment": "python-module-django-tests is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458007",
"Comment": "python3-module-django is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458008",
"Comment": "python3-module-django-dbbackend-mysql is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458009",
"Comment": "python3-module-django-dbbackend-psycopg2 is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458010",
"Comment": "python3-module-django-dbbackend-sqlite3 is earlier than 0:1.8.18-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171458011",
"Comment": "python3-module-django-tests is earlier than 0:1.8.18-alt1"
}
]
}
]
}
}
]
}