Medium severity5.3NVD Advisory· Published Jul 1, 2019· Updated Jun 17, 2026
CVE-2019-12781
CVE-2019-12781
Description
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | >= 2.1, < 2.1.10 | 2.1.10 |
DjangoPyPI | >= 2.2, < 2.2.3 | 2.2.3 |
DjangoPyPI | >= 1.11, < 1.11.22 | 1.11.22 |
Affected products
21- osv-coords14 versionspkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweedpkg:pypi/djangopkg:rpm/suse/python-Django&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-Django&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-Django1&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-Django1&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/python-Django&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Django&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/python-Django&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/python-Django5&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Django&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweed
< 2.2.4-lp151.2.3.1+ 13 more
- (no CPE)range: < 2.2.4-lp151.2.3.1
- (no CPE)range: < 4.2.14-1.1
- (no CPE)range: >= 2.1, < 2.1.10
- (no CPE)range: < 1.11.23-3.12.1
- (no CPE)range: < 1.11.23-3.12.1
- (no CPE)range: < 1.11.23-3.9.1
- (no CPE)range: < 1.11.23-3.9.1
- (no CPE)range: < 1.8.19-3.18.1
- (no CPE)range: < 6.0-1.1
- (no CPE)range: < 1.6.11-6.10.1
- (no CPE)range: < 2.2.4-bp151.3.3.1
- (no CPE)range: < 5.2.16-1.1
- (no CPE)range: < 1.11.23-3.12.1
- (no CPE)range: < 3.2.7-2.3
- Django/Djangodescription
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
21- www.openwall.com/lists/oss-security/2019/07/01/3nvdMailing ListPatchThird Party AdvisoryWEB
- docs.djangoproject.com/en/dev/releases/security/nvdPatchVendor Advisory
- www.djangoproject.com/weblog/2019/jul/01/security-releases/nvdPatchVendor Advisory
- www.securityfocus.com/bid/109018nvdThird Party Advisory
- github.com/advisories/GHSA-6c7v-2f49-8h26ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-12781ghsaADVISORY
- seclists.org/bugtraq/2019/Jul/10nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20190705-0002/nvdThird Party Advisory
- usn.ubuntu.com/4043-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4476nvdThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.htmlnvdWEB
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.htmlnvdWEB
- docs.djangoproject.com/en/dev/releases/securityghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2019-10.yamlghsaWEB
- groups.google.com/forum/ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/5VXXWIOQGXOB7JCGJ3CVUW673LDHKEYLghsaWEB
- security.netapp.com/advisory/ntap-20190705-0002ghsaWEB
- usn.ubuntu.com/4043-1ghsaWEB
- www.djangoproject.com/weblog/2019/jul/01/security-releasesghsaWEB
- groups.google.com/forum/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VXXWIOQGXOB7JCGJ3CVUW673LDHKEYL/nvd
News mentions
0No linked articles in our index yet.