Логотип exploitDog
bind:CVE-2020-35681
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-35681

Количество 5

Количество 5

ubuntu логотип

CVE-2020-35681

почти 5 лет назад

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases this would result in a crash but, with correct timing, responses could be sent to the wrong client, resulting in potential leakage of session identifiers and other sensitive data. Note that this affects only the legacy Channels provided class, and not Django's similar ASGIHandler, available from Django 3.0.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2020-35681

около 5 лет назад

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases this would result in a crash but, with correct timing, responses could be sent to the wrong client, resulting in potential leakage of session identifiers and other sensitive data. Note that this affects only the legacy Channels provided class, and not Django's similar ASGIHandler, available from Django 3.0.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2020-35681

почти 5 лет назад

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases this would result in a crash but, with correct timing, responses could be sent to the wrong client, resulting in potential leakage of session identifiers and other sensitive data. Note that this affects only the legacy Channels provided class, and not Django's similar ASGIHandler, available from Django 3.0.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2020-35681

почти 5 лет назад

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sen ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-v542-8q9x-cffc

почти 5 лет назад

Django Channels leakage of session identifiers using legacy AsgiHandler

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-35681

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases this would result in a crash but, with correct timing, responses could be sent to the wrong client, resulting in potential leakage of session identifiers and other sensitive data. Note that this affects only the legacy Channels provided class, and not Django's similar ASGIHandler, available from Django 3.0.

CVSS3: 7.4
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2020-35681

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases this would result in a crash but, with correct timing, responses could be sent to the wrong client, resulting in potential leakage of session identifiers and other sensitive data. Note that this affects only the legacy Channels provided class, and not Django's similar ASGIHandler, available from Django 3.0.

CVSS3: 7.4
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-35681

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases this would result in a crash but, with correct timing, responses could be sent to the wrong client, resulting in potential leakage of session identifiers and other sensitive data. Note that this affects only the legacy Channels provided class, and not Django's similar ASGIHandler, available from Django 3.0.

CVSS3: 7.4
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-35681

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sen ...

CVSS3: 7.4
1%
Низкий
почти 5 лет назад
github логотип
GHSA-v542-8q9x-cffc

Django Channels leakage of session identifiers using legacy AsgiHandler

CVSS3: 7.4
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу