VYPR
Medium severity6.1NVD Advisory· Published Apr 4, 2017· Updated May 13, 2026

CVE-2017-7234

CVE-2017-7234

Description

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the `django.views.static.serve()` view could redirect to any other domain, aka an open redirect vulnerability.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
DjangoPyPI
>= 1.10, < 1.10.71.10.7
DjangoPyPI
>= 1.9, < 1.9.131.9.13
DjangoPyPI
>= 1.8, < 1.8.181.8.18

Affected products

49
  • cpe:2.3:a:djangoproject:django:1.10.0:*:*:*:*:*:*:*+ 48 more
    • cpe:2.3:a:djangoproject:django:1.10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.0:a1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.0:b1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.2:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.3:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.4:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.5:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.10.6:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.0:a1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.0:b1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.0:b2:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.0:c1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.10:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.11:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.12:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.13:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.14:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.15:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.16:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.17:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.6:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.7:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.8:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.9:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.10:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.11:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.12:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.3:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.4:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.5:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.6:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.7:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.8:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9.9:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9:a1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9:b1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9:rc1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.9:rc2:*:*:*:*:*:*

Patches

3

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

13

News mentions

0

No linked articles in our index yet.