GCVE-VVD-MAGEIA-2016-96
Advisory Published
Vulnetix · Advisory published July 5, 2016
Mark Striemer discovered that Django incorrectly handled user-supplied redirect URLs containing basic authentication credentials. A remote attacker could possibly use this issue to perform a cross-site scripting attack or a malicious redirect. (CVE-2016-2512) Sjoerd Job Postmus discovered that Django incorrectly handled timing when doing password hashing operations. A remote attacker could possibly use this issue to perform user enumeration. (CVE-2016-2513)

Affected Products

VendorProductVersionsPlatforms
Mageiacantata0 (affected), 1.4.1-7.2.mga5 (unaffected)
Mageiapython-django0 (affected), 1.8.10-1.mga5 (unaffected), 0 (affected), 1.8.10-1.mga5 (unaffected)

Aliases

Transitive aliases

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.