Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.844076
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-4043-1)
Summary:The remote host is missing an update for the 'python-django' package(s) announced via the USN-4043-1 advisory.
Description:Summary:
The remote host is missing an update for the 'python-django' package(s) announced via the USN-4043-1 advisory.

Vulnerability Insight:
It was discovered that Django incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 18.10 and Ubuntu 19.04.
(CVE-2019-12308)

Gavin Wahl discovered that Django incorrectly handled HTTP detection when used behind a reverse-proxy. Client requests made via HTTP would cause incorrect API results and would not be redirected to HTTPS, contrary to expectations. (CVE-2019-12781)

Affected Software/OS:
'python-django' package(s) on Ubuntu 16.04, Ubuntu 18.04, Ubuntu 18.10, Ubuntu 19.04.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-12308
BugTraq ID: 108559
http://www.securityfocus.com/bid/108559
Bugtraq: 20190708 [SECURITY] [DSA 4476-1] python-django security update (Google Search)
https://seclists.org/bugtraq/2019/Jul/10
Debian Security Information: DSA-4476 (Google Search)
https://www.debian.org/security/2019/dsa-4476
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/USYRARSYB7PE3S2ZQO7PZNWMH7RPGL5G/
https://security.gentoo.org/glsa/202004-17
https://docs.djangoproject.com/en/dev/releases/security/
https://groups.google.com/forum/#!topic/django-announce/GEbHU7YoVz8
https://lists.debian.org/debian-lts-announce/2019/06/msg00001.html
https://lists.debian.org/debian-lts-announce/2019/07/msg00001.html
http://www.openwall.com/lists/oss-security/2019/06/03/2
SuSE Security Announcement: openSUSE-SU-2019:1839 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html
SuSE Security Announcement: openSUSE-SU-2019:1872 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html
https://usn.ubuntu.com/4043-1/
Common Vulnerability Exposure (CVE) ID: CVE-2019-12781
BugTraq ID: 109018
http://www.securityfocus.com/bid/109018
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5VXXWIOQGXOB7JCGJ3CVUW673LDHKEYL/
https://groups.google.com/forum/#!topic/django-announce/Is4kLY9ZcZQ
http://www.openwall.com/lists/oss-security/2019/07/01/3
CopyrightCopyright (C) 2019 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.