Описание
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 1.7.9-1ubuntu2 |
| esm-infra-legacy/trusty | released | 1.6.1-2ubuntu0.10 |
| precise | released | 1.3.1-4ubuntu1.18 |
| trusty | released | 1.6.1-2ubuntu0.10 |
| trusty/esm | released | 1.6.1-2ubuntu0.10 |
| upstream | released | 1.4.22,1.7.10,1.8.4 |
| vivid | released | 1.7.6-1ubuntu2.2 |
Показывать по
5 Medium
CVSS2
Связанные уязвимости
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache ...
Denial-of-service possibility in logout() view by filling session store
Уязвимость фреймворка для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании
5 Medium
CVSS2