CVE-2019-3498

Description

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
1.439

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-3498 are fixed in Python-django 1.11.18Windows
Vulnerabilities CVE-2019-3498 are fixed in Python-django 2.0.10Windows
Vulnerabilities CVE-2019-3498 are fixed in Python-django 2.1.5Windows
High-level Python web development framework (USN-3591-1) python-django_1.6.11-0ubuntu1.3_all.debLinux
High-level Python web development framework (USN-3851-1) python-django_1.6.11-0ubuntu1.3_all.debLinux
High-level Python web development framework (USN-3851-1) python-django_1.11.15-1ubuntu1.1_all.debLinux
High-level Python web development framework (USN-3851-1) python3-django_1.11.15-1ubuntu1.1_all.debLinux
python-django security update(DSA-4363-1) python-django_1.10.7-2+deb9u4_all.debLinux
Vulnerabilities CVE-2019-3498 are fixed in Python-django for linux 1.11.18Linux
Vulnerabilities CVE-2019-3498 are fixed in Python-django for linux 2.0.10Linux
Vulnerabilities CVE-2019-3498 are fixed in Python-django for linux 2.1.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234