Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-3982

Опубликовано: 02 июн. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

РелизСтатусПримечание
devel

not-affected

1.7.6-1ubuntu2
esm-infra-legacy/trusty

not-affected

precise

not-affected

trusty

not-affected

trusty/esm

not-affected

upstream

released

1.8.2
utopic

not-affected

vivid

not-affected

Показывать по

EPSS

Процентиль: 55%
0.00322
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
около 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

nvd
около 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

debian
около 10 лет назад

The session.flush function in the cached_db backend in Django 1.8.x be ...

CVSS3: 7.5
github
около 3 лет назад

Django allows user sessions hijacking via an empty string in the session key

EPSS

Процентиль: 55%
0.00322
Низкий

5 Medium

CVSS2