Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x88j-93vc-wpmp

Опубликовано: 23 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 4

Описание

Session manipulation in Django

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.2.7

1.2.7

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.3, < 1.3.1

1.3.1

EPSS

Процентиль: 76%
0.01022
Низкий

6.9 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 13 лет назад

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.

nvd
больше 13 лет назад

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.

debian
больше 13 лет назад

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, ...

EPSS

Процентиль: 76%
0.01022
Низкий

6.9 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-20