In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.
| Software | From | Fixed in |
|---|---|---|
| djangoproject / django | 1.11 | 1.11.18 |
| djangoproject / django | 2.0 | 2.0.10 |
| djangoproject / django | 2.1 | 2.1.5 |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 18.04 | 18.04.x |
| canonical / ubuntu_linux | 18.10 | 18.10.x |
| fedoraproject / fedora | 28 | 28.x |
Django
|
- | 1.11.18 |
Django
|
2.0.0 | 2.0.10 |
Django
|
2.1.0 | 2.1.5 |