CVE-2021-46898

views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vonautomatisch:django_grappelli:*:*:*:*:*:*:*:*

History

30 Oct 2023, 15:56

Type Values Removed Values Added
First Time Vonautomatisch
Vonautomatisch django Grappelli
CPE cpe:2.3:a:vonautomatisch:django_grappelli:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-601
References (MISC) https://github.com/sehmaschine/django-grappelli/issues/975 - (MISC) https://github.com/sehmaschine/django-grappelli/issues/975 - Exploit, Issue Tracking
References (MISC) https://github.com/sehmaschine/django-grappelli/commit/4ca94bcda0fa2720594506853d85e00c8212968f - (MISC) https://github.com/sehmaschine/django-grappelli/commit/4ca94bcda0fa2720594506853d85e00c8212968f - Patch
References (MISC) https://github.com/sehmaschine/django-grappelli/compare/2.15.1...2.15.2 - (MISC) https://github.com/sehmaschine/django-grappelli/compare/2.15.1...2.15.2 - Release Notes
References (MISC) https://github.com/sehmaschine/django-grappelli/pull/976 - (MISC) https://github.com/sehmaschine/django-grappelli/pull/976 - Patch

22 Oct 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-22 19:15

Updated : 2023-12-10 15:14


NVD link : CVE-2021-46898

Mitre link : CVE-2021-46898

CVE.ORG link : CVE-2021-46898


JSON object : View

Products Affected

vonautomatisch

  • django_grappelli
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')