Description
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
Remediation
References
Related Vulnerabilities
Jetty CVE-2020-27218 Vulnerability (CVE-2020-27218)
Oracle Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2001-1371)
Drupal Core 9.0.x Multiple Cross-Site Scripting Vulnerabilities (9.0.0 - 9.0.5)
WordPress Plugin Delete Comments By Status Multiple Cross-Site Scripting Vulnerabilities (1.5.2)
WordPress Plugin verwei.se-WordPress-Twitter Cross-Site Scripting (1.0.2)