Lucene search

K
githubGitHub Advisory DatabaseGHSA-Q7Q2-QF2Q-RW3W
HistoryMay 17, 2022 - 3:07 a.m.

Django Vulnerable to Cache Poisoning

2022-05-1703:07:00
CWE-349
GitHub Advisory Database
github.com
16
django
cache poisoning
vulnerability
version 1.4
version 1.5
version 1.6
version 1.7b4
sensitive information
remote attackers

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS

0.005

Percentile

76.3%

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

Affected configurations

Vulners
Node
djangoRange<1.7b4
OR
djangoRange<1.6.5
OR
djangoRange<1.5.8
OR
djangoRange<1.4.13
VendorProductVersionCPE
*django*cpe:2.3:a:*:django:*:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS

0.005

Percentile

76.3%