Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-4140

Опубликовано: 19 окт. 2011
Источник: debian
EPSS Низкий

Описание

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers to trigger unauthenticated forged requests via vectors involving a DNS CNAME record and a web page containing JavaScript code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed1.3.1-1package

EPSS

Процентиль: 60%
0.004
Низкий

Связанные уязвимости

nvd
больше 13 лет назад

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers to trigger unauthenticated forged requests via vectors involving a DNS CNAME record and a web page containing JavaScript code.

CVSS3: 7.5
github
почти 7 лет назад

Django Cross-Site Request Forgery vulnerability

EPSS

Процентиль: 60%
0.004
Низкий