Vulnerability Description
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Djangoproject | Django | >= 2.2, < 2.2.13 |
| Fedoraproject | Fedora | 32 |
| Canonical | Ubuntu Linux | 14.04 |
| Netapp | Sra Plugin | - |
| Netapp | Steelstore Cloud Integrated Storage | - |
| Debian | Debian Linux | 9.0 |
| Oracle | Zfs Storage Appliance Kit | 8.8 |
Related Weaknesses (CWE)
References
- https://docs.djangoproject.com/en/3.0/releases/security/Release NotesVendor Advisory
- https://groups.google.com/forum/#%21msg/django-announce/pPEmb2ot4Fo/X-SMalYSBAAJ
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20200611-0002/Third Party Advisory
- https://usn.ubuntu.com/4381-1/Third Party Advisory
- https://usn.ubuntu.com/4381-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4705Third Party Advisory
- https://www.djangoproject.com/weblog/2020/jun/03/security-releases/Release NotesVendor Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatchThird Party Advisory
- https://docs.djangoproject.com/en/3.0/releases/security/Release NotesVendor Advisory
- https://groups.google.com/forum/#%21msg/django-announce/pPEmb2ot4Fo/X-SMalYSBAAJ
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20200611-0002/Third Party Advisory
- https://usn.ubuntu.com/4381-1/Third Party Advisory
- https://usn.ubuntu.com/4381-2/Third Party Advisory
FAQ
What is CVE-2020-13596?
CVE-2020-13596 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility o...
How severe is CVE-2020-13596?
CVE-2020-13596 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13596?
Check the references section above for vendor advisories and patch information. Affected products include: Djangoproject Django, Fedoraproject Fedora, Canonical Ubuntu Linux, Netapp Sra Plugin, Netapp Steelstore Cloud Integrated Storage.