CVE-2018-14574
medium · 6.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
6.1
CVSS
25.5%
EPSS (exploit prob.)
98th
EPSS percentile
2018-08-03
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-601
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| djangoproject | django | >= 1.11, < 1.11.15 |
| djangoproject | django | >= 2.0, < 2.0.8 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 18.04 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/104970
- http://www.securitytracker.com/id/1041403
- https://access.redhat.com/errata/RHSA-2019:0265
- https://usn.ubuntu.com/3726-1/
- https://www.debian.org/security/2018/dsa-4264
- https://www.djangoproject.com/weblog/2018/aug/01/security-releases/
- http://www.securityfocus.com/bid/104970
- http://www.securitytracker.com/id/1041403
- https://access.redhat.com/errata/RHSA-2019:0265
- https://usn.ubuntu.com/3726-1/
- https://www.debian.org/security/2018/dsa-4264
- https://www.djangoproject.com/weblog/2018/aug/01/security-releases/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-14574