Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3982

Опубликовано: 02 июн. 2015
Источник: debian

Описание

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangonot-affectedpackage

Примечания

  • https://www.djangoproject.com/weblog/2015/may/20/security-release/

Связанные уязвимости

ubuntu
около 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

redhat
около 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

nvd
около 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

CVSS3: 7.5
github
около 3 лет назад

Django allows user sessions hijacking via an empty string in the session key