VDB
ALPINE-CVE-2017-7234
ALPINE-CVE-2017-7234
PUBLISHED
CVSS 6.099999904632568 MEDIUM
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
Risk Scores
CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.11 | py3-django | 1.8.12-r0, 1.8.3-r0, 1.8.16-r0 |
| Alpine:v3.2 | py-django | 1.8.3-r1, 1.8.3-r0, 1.8.16-r0 |
| Alpine:v3.5 | py-django | 1.5.8-r0, 1.2.5-r0, 1.2.5-r1 |
| Alpine:v3.7 | py-django | 1.5.5-r0, 1.5.6-r0, 1.5.7-r0 |
| Alpine:v3.12 | py3-django | 1.5.7-r0, 1.5.5-r0, 1.5.1-r0 |
| Alpine:v3.6 | py-django | 1.6.5-r0, 0, 1.10.5-r0 |
| Alpine:v3.4 | py-django | 1.5.8-r0, 0, 1.2.5-r0 |
| Alpine:v3.10 | py-django | 1.5.1-r0, 1.5.5-r0, 1.5.6-r0 |
| Alpine:v3.8 | py-django | 1.8.14-r0, 1.8.15-r0, 1.8.16-r0 |
| Alpine:v3.3 | py-django | 1.8.12-r0, 1.8.7-r0, 1.8.6-r0 |
| Alpine:v3.9 | py-django | 0, 1.8.3-r0, 1.8.16-r0 |
Timeline
- Apr 4, 2017 CVE Published
- Nov 19, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch