Lucene search

K
githubGitHub Advisory DatabaseGHSA-625G-GX8C-XCMG
HistoryMay 14, 2022 - 2:09 a.m.

Django Middleware Enables Session Hijacking

2022-05-1402:09:22
CWE-287
GitHub Advisory Database
github.com
13

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

73.3%

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

Affected configurations

Vulners
Node
django-registration_projectdjango-registrationRange<1.6.6django
OR
django-registration_projectdjango-registrationRange<1.5.9django
OR
django-registration_projectdjango-registrationRange<1.4.14django
CPENameOperatorVersion
djangolt1.6.6
djangolt1.5.9
djangolt1.4.14

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

73.3%