PT-2014-3650 · Django Software Foundation+1 · Django+1

David Greisen

·

Published

2014-08-26

·

Updated

2022-05-14

·

CVE-2014-0482

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Django versions 1.4.x through 1.4.13 Django versions 1.5.x through 1.5.8 Django versions 1.6.x through 1.6.5 Django versions 1.7 before release candidate 3
Description The issue allows remote authenticated users to hijack web sessions via vectors related to the REMOTE USER header when using the contrib.auth.backends.RemoteUserBackend backend with the contrib.auth.middleware.RemoteUserMiddleware middleware.
Recommendations For Django versions 1.4.x through 1.4.13, update to version 1.4.14 or later. For Django versions 1.5.x through 1.5.8, update to version 1.5.9 or later. For Django versions 1.6.x through 1.6.5, update to version 1.6.6 or later. For Django versions 1.7 before release candidate 3, update to release candidate 3 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0482
DLA-65-1
DSA-3010-1
GHSA-625G-GX8C-XCMG
MGASA-2014-0366
PYSEC-2014-6
SUSE-SU-2015:0563-1
SUSE-SU-2015:0695-1
USN-2347-1

Affected Products

Django
Ubuntu