Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2014-3730

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\djangoproject.com."

  • Published: May 16, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-3730
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N

CWEs:

Software From Fixed in
canonical / ubuntu_linux 13.10 13.10.x
canonical / ubuntu_linux 12.10 12.10.x
canonical / ubuntu_linux 14.04 14.04.x
canonical / ubuntu_linux 12.04 12.04.x
canonical / ubuntu_linux 10.04 10.04.x
djangoproject / django 1.4.12 1.4.12.x
djangoproject / django 1.4.9 1.4.9.x
djangoproject / django 1.4.10 1.4.10.x
djangoproject / django 1.4.6 1.4.6.x
djangoproject / django 1.4.4 1.4.4.x
djangoproject / django 1.4.5 1.4.5.x
djangoproject / django 1.4.2 1.4.2.x
djangoproject / django 1.4.11 1.4.11.x
djangoproject / django 1.4.7 1.4.7.x
djangoproject / django 1.4.8 1.4.8.x
djangoproject / django 1.4 1.4.x
djangoproject / django 1.4.1 1.4.1.x
djangoproject / django 1.7-beta1 1.7-beta1.x
djangoproject / django 1.7-beta3 1.7-beta3.x
djangoproject / django 1.7-beta2 1.7-beta2.x
opensuse / opensuse 12.3 12.3.x
opensuse / opensuse 13.1 13.1.x
djangoproject / django 1.6-beta4 1.6-beta4.x
djangoproject / django 1.6-beta2 1.6-beta2.x
djangoproject / django 1.6.3 1.6.3.x
djangoproject / django 1.6.4 1.6.4.x
djangoproject / django 1.6 1.6.x
djangoproject / django 1.6.1 1.6.1.x
djangoproject / django 1.6.2 1.6.2.x
djangoproject / django 1.6-beta1 1.6-beta1.x
djangoproject / django 1.6-beta3 1.6-beta3.x
debian / debian_linux 8.0 8.0.x
debian / debian_linux 7.0 7.0.x
djangoproject / django 1.5 1.5.x
djangoproject / django 1.5.7 1.5.7.x
djangoproject / django 1.5.1 1.5.1.x
djangoproject / django 1.5.3 1.5.3.x
djangoproject / django 1.5.4 1.5.4.x
djangoproject / django 1.5-beta 1.5-beta.x
djangoproject / django 1.5.5 1.5.5.x
djangoproject / django 1.5.2 1.5.2.x
djangoproject / django 1.5-alpha 1.5-alpha.x
djangoproject / django 1.5.6 1.5.6.x