CVE-2020-25626
published 2020-09-30CVE-2020-25626: A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.29%
67.2th percentile
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious tags, leading to a cross-site-scripting (XSS) vulnerability.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | djangorestframework | < djangorestframework 3.12.1-1 (bookworm) | djangorestframework 3.12.1-1 (bookworm) |
| encode | django_rest_framework | < 3.12.0 | 3.12.0 |
| encode | django_rest_framework | — | — |
| redhat | ceph_storage | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cross-site Scripting (XSS) in Django REST Framework
ghsa·2021-03-19
CVE-2020-25626 [MEDIUM] CWE-20 Cross-site Scripting (XSS) in Django REST Framework
Cross-site Scripting (XSS) in Django REST Framework
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious tags, leading to a cross-site-scripting (XSS) vulnerability.
OSV
Cross-site Scripting (XSS) in Django REST Framework
osv·2021-03-19
CVE-2020-25626 [MEDIUM] Cross-site Scripting (XSS) in Django REST Framework
Cross-site Scripting (XSS) in Django REST Framework
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious tags, leading to a cross-site-scripting (XSS) vulnerability.
OSV
CVE-2020-25626: A flaw was found in Django REST Framework versions before 3
osv·2020-09-30·CVSS 6.1
CVE-2020-25626 [MEDIUM] CVE-2020-25626: A flaw was found in Django REST Framework versions before 3
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious tags, leading to a cross-site-scripting (XSS) vulnerability.
Red Hat
django-rest-framework: XSS Vulnerability in API viewer
vendor_redhat·2020-09-30·CVSS 6.1
CVE-2020-25626 [MEDIUM] CWE-20 django-rest-framework: XSS Vulnerability in API viewer
django-rest-framework: XSS Vulnerability in API viewer
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious tags, leading to a cross-site-scripting (XSS) vulnerability.
A flaw was found in the Django REST Framework. When using the browseable API viewer, the Django REST Framework fails to properly escape certain strings that come from user input. This flaw allows a user to control those strings to inject malicious tags, leading to a cross-site-scripting (XSS) vulnerability.
Statement: In Red Hat Ceph Storage 2, python-djangorestframework is embedded in calamar
Debian
CVE-2020-25626: djangorestframework - A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11...
vendor_debian·2020·CVSS 6.1
CVE-2020-25626 [MEDIUM] CVE-2020-25626: djangorestframework - A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11...
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious tags, leading to a cross-site-scripting (XSS) vulnerability.
Scope: local
bookworm: resolved (fixed in 3.12.1-1)
bullseye: resolved (fixed in 3.12.1-1)
forky: resolved (fixed in 3.12.1-1)
sid: resolved (fixed in 3.12.1-1)
trixie: resolved (fixed in 3.12.1-1)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1878635https://security.netapp.com/advisory/ntap-20201016-0003/https://www.debian.org/security/2022/dsa-5186https://bugzilla.redhat.com/show_bug.cgi?id=1878635https://security.netapp.com/advisory/ntap-20201016-0003/https://www.debian.org/security/2022/dsa-5186
2020-09-30
Published