Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-1418

Опубликовано: 14 мая 2014
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3DjangoWill not fix
Red Hat OpenStack Platform 4DjangoWill not fix
Red Hat Subscription Asset ManagerDjangoWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1097500Django: cached data possibly served to the wrong session

EPSS

Процентиль: 66%
0.00512
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

nvd
около 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

debian
около 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 ...

CVSS3: 7.4
github
около 3 лет назад

Django Vulnerable to Cache Poisoning

EPSS

Процентиль: 66%
0.00512
Низкий

5.8 Medium

CVSS2