CVE-2019-3498
Description
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.
Risk Information
Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
1.439
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2019-3498 are fixed in Python-django 1.11.18 | Windows |
| Vulnerabilities CVE-2019-3498 are fixed in Python-django 2.0.10 | Windows |
| Vulnerabilities CVE-2019-3498 are fixed in Python-django 2.1.5 | Windows |
| High-level Python web development framework (USN-3591-1) python-django_1.6.11-0ubuntu1.3_all.deb | Linux |
| High-level Python web development framework (USN-3851-1) python-django_1.6.11-0ubuntu1.3_all.deb | Linux |
| High-level Python web development framework (USN-3851-1) python-django_1.11.15-1ubuntu1.1_all.deb | Linux |
| High-level Python web development framework (USN-3851-1) python3-django_1.11.15-1ubuntu1.1_all.deb | Linux |
| python-django security update(DSA-4363-1) python-django_1.10.7-2+deb9u4_all.deb | Linux |
| Vulnerabilities CVE-2019-3498 are fixed in Python-django for linux 1.11.18 | Linux |
| Vulnerabilities CVE-2019-3498 are fixed in Python-django for linux 2.0.10 | Linux |
| Vulnerabilities CVE-2019-3498 are fixed in Python-django for linux 2.1.5 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234