PT-2011-4857 · Django Software Foundation · Django

Jan Lieskovsky

·

Published

2011-10-19

·

Updated

2022-05-14

·

CVE-2011-4139

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Django versions prior to 1.2.7 Django versions 1.3.x prior to 1.3.1
Description The issue allows remote attackers to conduct cache poisoning attacks by crafting a request that exploits how Django constructs a full URL using a request's HTTP Host header in certain circumstances.
Recommendations For Django versions prior to 1.2.7, update to version 1.2.7 or later. For Django versions 1.3.x prior to 1.3.1, update to version 1.3.1 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4139
DSA-2332-1
GHSA-RM2J-X595-Q9CJ
PYSEC-2011-4

Affected Products

Django