CVE-2012-3442

Source
https://cve.org/CVERecord?id=CVE-2012-3442
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2012-3442.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2012-3442
Aliases
Downstream
Withdrawn
2026-01-27T04:11:18.032411Z
Published
2012-07-31T17:55:01Z
Modified
2026-01-27T04:11:18.032411Z
Summary
[none]
Details

The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL.

References

Affected packages