Hide Forgot
A flaw was found in Django REST Framework. When using the browseable API viewer, DRF fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a cross-site-scripting (XSS) vulnerability.
Acknowledgments: Name: Lior Ethan (Red Hat), Ryan Petrello (Red Hat)
This issue has been addressed in the following products: Red Hat Ansible Tower 3.7 for RHEL 7 Via RHSA-2020:4136 https://access.redhat.com/errata/RHSA-2020:4136
This issue has been addressed in the following products: Red Hat Ansible Tower 3.6 for RHEL 7 Via RHSA-2020:4137 https://access.redhat.com/errata/RHSA-2020:4137
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-25626
Statement: In Red Hat Ceph Storage 2, python-djangorestframework is embedded in calamari-server. However, calamari-server is no longer supported and will not be fixed.