Open Redirect Affecting django-revproxy package, versions [,0.9.7)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DJANGOREVPROXY-40112
  • published14 Sept 2017
  • disclosed17 Sept 2015
  • creditUnknown

Introduced: 17 Sep 2015

CVE NOT AVAILABLE CWE-601  (opens in a new tab)

Overview

django-revproxy is a simple reverse proxy using Django. It allows to use Django as a reverse Proxy to HTTP requets. It also allows to use Django as an authentication Proxy.

Affected versions of this package are vulnerable to Open Redirect attacks. When a colon is present in the URL path, the urljoin method ignores the upstream request and redirects it to a path cntrolled by an attacker, possibly causing content injection.

CVSS Scores

version 3.1