Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2061 | Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. |
Github GHSA |
GHSA-gw84-84pc-xp82 | Cross-site Scripting in djangorestframework |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 31 Dec 2024 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
Sat, 28 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.4::el8 cpe:/a:redhat:ansible_automation_platform:2.4::el9 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-12-31T10:10:34.187Z
Reserved: 2023-12-22T12:33:20.120Z
Link: CVE-2024-21520
Updated: 2024-08-01T22:20:40.905Z
Status : Awaiting Analysis
Published: 2024-06-26T05:15:50.093
Modified: 2024-12-31T10:15:06.317
Link: CVE-2024-21520
OpenCVE Enrichment
No data.
EUVD
Github GHSA