CVE-2014-3730

Source
https://cve.org/CVERecord?id=CVE-2014-3730
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-3730.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-3730
Aliases
Downstream
Withdrawn
2026-01-27T04:12:45Z
Published
2014-05-16T15:55:05Z
Modified
2026-04-16T01:48:15Z
Summary
[none]
Details

The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\djangoproject.com."

References

Affected packages