Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0219

Опубликовано: 13 янв. 2015
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-djangoNot affected
Red Hat OpenStack Platform 4Django14Not affected
Red Hat Subscription Asset ManagerDjangoNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=1179672Django: WSGI header spoofing via underscore/dash conflation

EPSS

Процентиль: 86%
0.03128
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

nvd
почти 11 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

debian
почти 11 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allo ...

CVSS3: 5.3
github
больше 3 лет назад

Django WSGI Header Spoofing Vulnerability

EPSS

Процентиль: 86%
0.03128
Низкий

5.8 Medium

CVSS2