CVE-2016-6186

Related Vulnerabilities: CVE-2016-6186  

A cross-site scripting (XSS) flaw was found in Django. An attacker could exploit the unsafe usage of JavaScript's Element.innerHTML to forge content in the admin's add/change related pop-up. Element.textContent is now used to prevent XSS data execution.

A cross-site scripting (XSS) flaw was found in Django. An attacker could exploit the unsafe usage of JavaScript's Element.innerHTML to forge content in the admin's add/change related pop-up. Element.textContent is now used to prevent XSS data execution.

Find out more about CVE-2016-6186 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None

CVSS v3 metrics

CVSS3 Base Score 6.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Impact Low
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat OpenStack Platform 8.0 (Liberty) (python-django) RHSA-2016:1596 2016-08-11
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 (python-django) RHSA-2016:1595 2016-08-11
Red Hat Enterprise Linux OpenStack Platform 8.0 Operational Tools for RHEL 7 (python-django) RHSA-2016:1594 2016-08-10

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 Django Will not fix
Red Hat OpenStack Platform 9.0 python-django Not affected
Red Hat OpenStack Platform 10 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) python-django Not affected
Red Hat Ceph Storage 1.3 Django Will not fix

Acknowledgements

Red Hat would like to thank the upstream Django project for reporting this issue.