CVE-2017-12794
Ubuntu Security Notice USN-3559-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with "DEBUG = True" (which makes this page accessible) in your production settings.
En Django versiones 1.10.x anteriores a la 1.10.8 y versiones 1.11.x anteriores a la 1.11.5, se deshabilitó la función de autoescapado HTML en una parte de la plantilla para la página de depuración technical 500. En las condiciones adecuadas, esto permitiría un ataque de Cross-Site Scripting (XSS). Esta vulnerabilidad no debería afectar a la mayoría de sitios de producción, ya que no se debería ejecutar el programa con "DEBUG = True" (lo que hace que esta página sea accesible) en la configuración de producción.
It was discovered that Django incorrectly handled certain requests. An attacker could possibly use this to access sensitive information.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-10 CVE Reserved
- 2017-09-07 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100643 | Third Party Advisory | |
http://www.securitytracker.com/id/1039264 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.djangoproject.com/weblog/2017/sep/05/security-releases | 2018-03-16 |
URL | Date | SRC |
---|---|---|
https://usn.ubuntu.com/3559-1 | 2018-03-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.10.0 Search vendor "Djangoproject" for product "Django" and version "1.10.0" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.10.1 Search vendor "Djangoproject" for product "Django" and version "1.10.1" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.10.2 Search vendor "Djangoproject" for product "Django" and version "1.10.2" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.10.3 Search vendor "Djangoproject" for product "Django" and version "1.10.3" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.10.4 Search vendor "Djangoproject" for product "Django" and version "1.10.4" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.10.5 Search vendor "Djangoproject" for product "Django" and version "1.10.5" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.10.6 Search vendor "Djangoproject" for product "Django" and version "1.10.6" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.10.7 Search vendor "Djangoproject" for product "Django" and version "1.10.7" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.11.0 Search vendor "Djangoproject" for product "Django" and version "1.11.0" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.11.1 Search vendor "Djangoproject" for product "Django" and version "1.11.1" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.11.2 Search vendor "Djangoproject" for product "Django" and version "1.11.2" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.11.3 Search vendor "Djangoproject" for product "Django" and version "1.11.3" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.11.4 Search vendor "Djangoproject" for product "Django" and version "1.11.4" | - |
Affected
|