PT-2011-4858 · Django · Django
Jan Lieskovsky
·
Published
2011-10-19
·
Updated
2018-07-23
·
CVE-2011-4140
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Django versions 1.2.0 through 1.2.7
Django versions 1.3.0 through 1.3.1
Description
The issue concerns the CSRF protection mechanism, which does not properly handle web-server configurations that support arbitrary HTTP Host headers. This allows remote attackers to trigger unauthenticated forged requests through vectors involving a DNS CNAME record and a web page containing JavaScript code.
Recommendations
For Django versions 1.2.0 through 1.2.7, update to a version that properly handles web-server configurations supporting arbitrary HTTP Host headers.
For Django versions 1.3.0 through 1.3.1, update to a version that properly handles web-server configurations supporting arbitrary HTTP Host headers.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django