Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0219

Опубликовано: 13 янв. 2015
Источник: redhat
CVSS2: 5.8

Описание

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-djangoNot affected
Red Hat OpenStack Platform 4Django14Not affected
Red Hat Subscription Asset ManagerDjangoNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=1179672Django: WSGI header spoofing via underscore/dash conflation

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

nvd
больше 10 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

debian
больше 10 лет назад

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allo ...

CVSS3: 5.3
github
около 3 лет назад

Django WSGI Header Spoofing Vulnerability

5.8 Medium

CVSS2