Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-4136

Опубликовано: 19 окт. 2011
Источник: debian
EPSS Низкий

Описание

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed1.3.1-1package

EPSS

Процентиль: 76%
0.01022
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.

nvd
больше 13 лет назад

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.

CVSS3: 4
github
почти 7 лет назад

Session manipulation in Django

EPSS

Процентиль: 76%
0.01022
Низкий