CVE-2017-12794

Related Vulnerabilities: CVE-2017-12794  

In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with "DEBUG = True" (which makes this page accessible) in your production settings.

The MITRE CVE dictionary describes this issue as:

In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with "DEBUG = True" (which makes this page accessible) in your production settings.

Find out more about CVE-2017-12794 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 4
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Changed
Confidentiality None
Integrity Impact Low
Availability Impact None

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 Django Not affected
Red Hat Storage Console 2 Django Not affected
Red Hat Storage Console 2 python-django Not affected
Red Hat Satellite 6 python-django Not affected
Red Hat OpenStack Platform Operational Tools 9 python-django Not affected
Red Hat OpenStack Platform 9.0 python-django Not affected
Red Hat OpenStack Platform 8.0 (Liberty) python-django Not affected
Red Hat OpenStack Platform 12.0 python-django Not affected
Red Hat OpenStack Platform 11.0 (Ocata) python-django Not affected
Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7 python-django Not affected
Red Hat OpenStack Platform 10 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 8.0 Operational Tools for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) python-django Not affected
Red Hat Ceph Storage 2 Django Not affected
Red Hat Ceph Storage 1.3 Django Not affected

External References