Medium severity6.1NVD Advisory· Published Apr 4, 2017· Updated May 13, 2026
CVE-2017-7234
CVE-2017-7234
Description
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the `django.views.static.serve()` view could redirect to any other domain, aka an open redirect vulnerability.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | >= 1.10, < 1.10.7 | 1.10.7 |
DjangoPyPI | >= 1.9, < 1.9.13 | 1.9.13 |
DjangoPyPI | >= 1.8, < 1.8.18 | 1.8.18 |
Affected products
49cpe:2.3:a:djangoproject:django:1.10.0:*:*:*:*:*:*:*+ 48 more
- cpe:2.3:a:djangoproject:django:1.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.0:a1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.0:b1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.2:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.3:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.4:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.5:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.10.6:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.0:a1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.0:b1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.0:b2:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.0:c1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.10:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.11:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.12:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.13:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.14:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.15:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.16:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.17:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.5:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.6:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.7:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.8:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.8.9:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.10:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.11:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.12:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.4:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.8:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9.9:*:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9:a1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9:b1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9:rc1:*:*:*:*:*:*
- cpe:2.3:a:djangoproject:django:1.9:rc2:*:*:*:*:*:*
Patches
32a9f6ef71b8ehttps://github.com/django/djangovia ghsa
4a6b945dffe8https://github.com/django/djangovia ghsa
5f1ffb07afc1https://github.com/django/djangovia ghsa
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
13- www.securityfocus.com/bid/97401nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-h4hv-m4h4-mhwgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-7234ghsaADVISORY
- www.djangoproject.com/weblog/2017/apr/04/security-releases/nvdVendor Advisory
- www.debian.org/security/2017/dsa-3835nvdWEB
- github.com/django/django/commit/2a9f6ef71b8e23fd267ee2be1be26dde8ab67037ghsaWEB
- github.com/django/django/commit/4a6b945dffe8d10e7cec107d93e6efaebfbded29ghsaWEB
- github.com/django/django/commit/5f1ffb07afc1e59729ce2b283124116d6c0659e4ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2017-10.yamlghsaWEB
- web.archive.org/web/20170429023907/http://www.securitytracker.com/id/1038177ghsaWEB
- web.archive.org/web/20170526042328/http://www.securityfocus.com/bid/97401ghsaWEB
- www.djangoproject.com/weblog/2017/apr/04/security-releasesghsaWEB
- www.securitytracker.com/id/1038177nvd
News mentions
0No linked articles in our index yet.