The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2634-1 | python-django security update |
EUVD |
EUVD-2012-0006 | The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values. |
Github GHSA |
GHSA-2655-q453-22f9 | Django Allows Arbitrary URL Generation |
Ubuntu USN |
USN-1632-1 | Django vulnerability |
Ubuntu USN |
USN-1757-1 | Django vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T20:42:53.672Z
Reserved: 2012-08-21T00:00:00.000Z
Link: CVE-2012-4520
No data.
Status : Deferred
Published: 2012-11-18T23:55:01.040
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-4520
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA
Ubuntu USN