CVE-2020-13596: Canonical Ubuntu Linux
Medium severity, CVSS 6.1. EPSS: 2.9% chance of exploitation in the next 30 days.
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Djangoproject Django: from 2.2, before 2.2.13 (fixed in 2.2.13); from 3.0, before 3.0.7 (fixed in 3.0.7)
- Fedoraproject Fedora: version 32 only
- Netapp SRA Plugin: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Oracle ZFS Storage Appliance Kit: version 8.8 only
Published 2020-06-03. Last modified 2026-06-17.