Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5964

Опубликовано: 18 авг. 2015
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.

It was found that certain Django functions would, in certain circumstances, create empty sessions. A remote attacker could use this flaw to fill up the session store or cause other users' session records to be evicted by requesting a large number of new sessions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6python-djangoFixedRHSA-2015:176610.09.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7python-djangoFixedRHSA-2015:176710.09.2015
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7python-djangoFixedRHSA-2015:189415.10.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1252891python-django: Denial-of-service possibility in logout() view by filling session store

EPSS

Процентиль: 83%
0.01997
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.

nvd
почти 10 лет назад

The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.

debian
почти 10 лет назад

The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache ...

CVSS3: 7.5
github
около 3 лет назад

Denial-of-service possibility in logout() view by filling session store

fstec
почти 10 лет назад

Уязвимость фреймворка для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 83%
0.01997
Низкий

5 Medium

CVSS2

Уязвимость CVE-2015-5964