Lucene search

K
cveRedhatCVE-2015-0219
HistoryJan 16, 2015 - 4:59 p.m.

CVE-2015-0219

2015-01-1616:59:18
CWE-17
redhat
web.nvd.nist.gov
66
django
cve-2015-0219
security
wsgi
http header
remote attackers

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.008

Percentile

82.2%

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

Affected configurations

Nvd
Node
djangoprojectdjangoRange1.4.17
OR
djangoprojectdjangoMatch1.6
OR
djangoprojectdjangoMatch1.6.1
OR
djangoprojectdjangoMatch1.6.2
OR
djangoprojectdjangoMatch1.6.3
OR
djangoprojectdjangoMatch1.6.4
OR
djangoprojectdjangoMatch1.6.5
OR
djangoprojectdjangoMatch1.6.6
OR
djangoprojectdjangoMatch1.6.7
OR
djangoprojectdjangoMatch1.6.8
OR
djangoprojectdjangoMatch1.6.9
OR
djangoprojectdjangoMatch1.7
OR
djangoprojectdjangoMatch1.7.1
OR
djangoprojectdjangoMatch1.7.2
VendorProductVersionCPE
djangoprojectdjango*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
djangoprojectdjango1.6cpe:2.3:a:djangoproject:django:1.6:*:*:*:*:*:*:*
djangoprojectdjango1.6.1cpe:2.3:a:djangoproject:django:1.6.1:*:*:*:*:*:*:*
djangoprojectdjango1.6.2cpe:2.3:a:djangoproject:django:1.6.2:*:*:*:*:*:*:*
djangoprojectdjango1.6.3cpe:2.3:a:djangoproject:django:1.6.3:*:*:*:*:*:*:*
djangoprojectdjango1.6.4cpe:2.3:a:djangoproject:django:1.6.4:*:*:*:*:*:*:*
djangoprojectdjango1.6.5cpe:2.3:a:djangoproject:django:1.6.5:*:*:*:*:*:*:*
djangoprojectdjango1.6.6cpe:2.3:a:djangoproject:django:1.6.6:*:*:*:*:*:*:*
djangoprojectdjango1.6.7cpe:2.3:a:djangoproject:django:1.6.7:*:*:*:*:*:*:*
djangoprojectdjango1.6.8cpe:2.3:a:djangoproject:django:1.6.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.008

Percentile

82.2%