CVE-2019-3498Injection in Django

Severity
6.5MEDIUMNVD
EPSS
1.4%
top 19.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateJan 14

Description

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDdjangoproject/django1.111.11.18+2
PyPIdjangoproject/django1.11a11.11.18+2

Also affects: Debian Linux 8.0, 9.0, Fedora 28, Ubuntu Linux 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

4
GHSA
Improper Input Validation in Django2019-01-14
OSV
Improper Input Validation in Django2019-01-14
OSV
CVE-2019-3498: In Django 12019-01-09
CVEList
CVE-2019-3498: In Django 12019-01-09

📋Vendor Advisories

3
Ubuntu
Django vulnerability2019-01-09
Red Hat
python-django: Content spoofing via URL path in default 404 page2019-01-07
Debian
CVE-2019-3498: python-django - In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an...2019

💬Community

4
Bugzilla
CVE-2019-3498 python-django: Content spoofing via URL path in default 404 page2019-01-07
Bugzilla
CVE-2019-3498 python-django: Content spoofing via URL path in default 404 page [epel-7]2019-01-07
Bugzilla
CVE-2019-3498 python-django: Content spoofing via URL path in default 404 page [fedora-all]2019-01-07
Bugzilla
CVE-2019-3498 django:1.6/python-django: Content spoofing via URL path in default 404 page [fedora-all]2019-01-07
CVE-2019-3498 — Injection in Djangoproject Django | cvebase