High severityNVD Advisory· Published Oct 19, 2011· Updated Jun 16, 2026
CVE-2011-4138
CVE-2011-4138
Description
The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity through a HEAD request, but then uses a GET request for the new target URL in the case of a redirect, which might allow remote attackers to trigger arbitrary GET requests with an unintended source IP address via a crafted Location header.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | < 1.2.7 | 1.2.7 |
DjangoPyPI | >= 1.3, < 1.3.1 | 1.3.1 |
Affected products
23cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*+ 21 more
- cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*range: <=1.2.6
- cpe:2.3:a:djangoproject:django:0.91:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:0.95:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:0.95.1:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:0.96:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.2.1:2:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.3:alpha1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.3:alpha2:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
15- openwall.com/lists/oss-security/2011/09/11/1nvdPatchWEB
- openwall.com/lists/oss-security/2011/09/13/2nvdPatchWEB
- bugzilla.redhat.com/show_bug.cginvdPatchWEB
- www.djangoproject.com/weblog/2011/sep/09/nvdPatchVendor Advisory
- www.djangoproject.com/weblog/2011/sep/10/127/nvdPatch
- github.com/advisories/GHSA-wxg3-mfph-qg9wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-4138ghsaADVISORY
- www.debian.org/security/2011/dsa-2332nvdWEB
- github.com/django/django/commit/1a76dbefdfc60e2d5954c0ba614c3d054ba9c3f0ghsaWEB
- github.com/django/django/commit/7268f8af86186518821d775c530d5558fd726930ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2011-3.yamlghsaWEB
- hermes.opensuse.org/messages/14700881nvdWEB
- www.djangoproject.com/weblog/2011/sep/09ghsaWEB
- www.djangoproject.com/weblog/2011/sep/10/127ghsaWEB
- secunia.com/advisories/46614nvd
News mentions
0No linked articles in our index yet.