PT-2011-4857 · Django Software Foundation · Django

Jan Lieskovsky

·

Publicado

2011-10-19

·

Atualizado

2022-05-14

·

CVE-2011-4139

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Django versions prior to 1.2.7 Django versions 1.3.x prior to 1.3.1
Description The issue allows remote attackers to conduct cache poisoning attacks by crafting a request that exploits how Django constructs a full URL using a request's HTTP Host header in certain circumstances.
Recommendations For Django versions prior to 1.2.7, update to version 1.2.7 or later. For Django versions 1.3.x prior to 1.3.1, update to version 1.3.1 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4139
DSA-2332-1
GHSA-RM2J-X595-Q9CJ
PYSEC-2011-4

Produtos afetados

Django