Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35192

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but SESSION_SAVE_EVERY_REQUEST is True. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

A flaw was found in Django. When the SESSION_SAVE_EVERY_REQUEST setting is enabled, response headers do not properly vary on cookies for unmodified sessions. This vulnerability allows a remote attacker to steal a user's session after the user visits a cached public page, leading to unauthorized access to their account.

Отчет

Moderate: A flaw in Django applications, when configured with SESSION_SAVE_EVERY_REQUEST enabled, allows for session theft. This occurs because response headers do not properly vary on cookies for unmodified sessions, enabling a remote attacker to steal a user's session after they visit a cached public page. This vulnerability requires a specific configuration and user interaction to be exploited.

Меры по смягчению последствий

To mitigate this issue, ensure that the SESSION_SAVE_EVERY_REQUEST setting in Django applications is set to False unless explicitly required for application functionality. Disabling this setting prevents the vulnerable condition where response headers do not properly vary on cookies for unmodified sessions on cached public pages. Consult your Django application's configuration for specific instructions on modifying this setting. A restart of the Django application or web server may be required for the change to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/aap-cloud-billing-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/controller-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/eda-controller-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-488
https://bugzilla.redhat.com/show_bug.cgi?id=2466807Django: Django: Session theft due to improper cookie handling with cached pages

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
nvd
3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
debian
3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Res ...

github
3 месяца назад

Django Uses Persistent Cookies Containing Sensitive Information

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость программной платформы для веб-приложений Django, связанная с возможностью отправки файла cookie-сеанса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

6.5 Medium

CVSS3