Vulnerability Description
In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with "DEBUG = True" (which makes this page accessible) in your production settings.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Djangoproject | Django | 1.10.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100643Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039264Third Party AdvisoryVDB Entry
- https://usn.ubuntu.com/3559-1/
- https://www.djangoproject.com/weblog/2017/sep/05/security-releases/PatchVendor Advisory
- http://www.securityfocus.com/bid/100643Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039264Third Party AdvisoryVDB Entry
- https://usn.ubuntu.com/3559-1/
- https://www.djangoproject.com/weblog/2017/sep/05/security-releases/PatchVendor Advisory
FAQ
What is CVE-2017-12794?
CVE-2017-12794 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cro...
How severe is CVE-2017-12794?
CVE-2017-12794 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12794?
Check the references section above for vendor advisories and patch information. Affected products include: Djangoproject Django.