REDHAT-BUG-2294457: XSS
Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the breaklongheaders template filter due to improper input sanitization before splitting and joining with <br> tags.
https://github.com/encode/django-rest-framework/commit/3b41f0124194430da957b119712978fa2266b642 https://github.com/encode/django-rest-framework/pull/9435 https://security.snyk.io/vuln/SNYK-PYTHON-DJANGORESTFRAMEWORK-7252137
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2294457?
REDHAT-BUG-2294457 is classified as a high severity vulnerability due to its potential for Cross-site Scripting (XSS) attacks.
How do I fix REDHAT-BUG-2294457?
To fix REDHAT-BUG-2294457, upgrade the Django REST Framework to version 3.15.2 or later.
What versions are affected by REDHAT-BUG-2294457?
Versions of the Django REST Framework prior to 3.15.2 are affected by REDHAT-BUG-2294457.
What type of vulnerability is REDHAT-BUG-2294457?
REDHAT-BUG-2294457 is a Cross-site Scripting (XSS) vulnerability caused by improper input sanitization.
Is user data at risk with REDHAT-BUG-2294457?
Yes, user data may be at risk due to potential XSS attacks that can exploit REDHAT-BUG-2294457.