Ubuntu Security Notice USN-3254-1

Discussion in 'News Aggregator' started by Packet Storm, 6 Apr 2017.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3254-1 - It was discovered that Django incorrectly handled numeric redirect URLs. A remote attacker could possibly use this issue to perform XSS attacks, and to use a Django server as an open redirect. Phithon Gong discovered that Django incorrectly handled certain URLs when the jango.views.static.serve view is being used. A remote attacker could possibly use a Django server as an open redirect.

    Continue reading...
     

Share This Page

Loading...