Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1418

Опубликовано: 16 мая 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 6.4

Описание

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

РелизСтатусПримечание
devel

released

1.6.1-2ubuntu0.3
esm-infra-legacy/trusty

not-affected

1.6.1-2ubuntu0.3
lucid

released

1.1.1-2ubuntu1.12
precise

released

1.3.1-4ubuntu1.11
quantal

released

1.4.1-2ubuntu0.7
saucy

released

1.5.4-1ubuntu1.3
trusty

released

1.6.1-2ubuntu0.3
trusty/esm

not-affected

1.6.1-2ubuntu0.3
upstream

released

1.6.5, 1.5.8, 1.4.13

Показывать по

6.4 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

nvd
около 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

debian
около 11 лет назад

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 ...

CVSS3: 7.4
github
около 3 лет назад

Django Vulnerable to Cache Poisoning

6.4 Medium

CVSS2