Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1418

Опубликовано: 16 мая 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 6.4

Описание

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

РелизСтатусПримечание
devel

released

1.6.1-2ubuntu0.3
esm-infra-legacy/trusty

released

1.6.1-2ubuntu0.3
lucid

released

1.1.1-2ubuntu1.12
precise

released

1.3.1-4ubuntu1.11
quantal

released

1.4.1-2ubuntu0.7
saucy

released

1.5.4-1ubuntu1.3
trusty

released

1.6.1-2ubuntu0.3
trusty/esm

released

1.6.1-2ubuntu0.3
upstream

released

1.6.5, 1.5.8, 1.4.13

Показывать по

6.4 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

nvd
больше 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

debian
больше 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 ...

CVSS3: 7.4
github
больше 3 лет назад

Django Vulnerable to Cache Poisoning

6.4 Medium

CVSS2