Lucene search

K
nvd[email protected]NVD:CVE-2014-0482
HistoryAug 26, 2014 - 2:55 p.m.

CVE-2014-0482

2014-08-2614:55:05
CWE-287
web.nvd.nist.gov

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.3%

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

Affected configurations

NVD
Node
opensuseopensuseMatch12.3
OR
opensuseopensuseMatch13.1
Node
djangoprojectdjangoMatch1.6-
OR
djangoprojectdjangoMatch1.6beta1
OR
djangoprojectdjangoMatch1.6beta2
OR
djangoprojectdjangoMatch1.6beta3
OR
djangoprojectdjangoMatch1.6beta4
OR
djangoprojectdjangoMatch1.6.1
OR
djangoprojectdjangoMatch1.6.2
OR
djangoprojectdjangoMatch1.6.3
OR
djangoprojectdjangoMatch1.6.4
OR
djangoprojectdjangoMatch1.6.5
Node
djangoprojectdjangoRange1.4.13
OR
djangoprojectdjangoMatch1.4
OR
djangoprojectdjangoMatch1.4.1
OR
djangoprojectdjangoMatch1.4.2
OR
djangoprojectdjangoMatch1.4.4
OR
djangoprojectdjangoMatch1.4.5
OR
djangoprojectdjangoMatch1.4.6
OR
djangoprojectdjangoMatch1.4.7
OR
djangoprojectdjangoMatch1.4.8
OR
djangoprojectdjangoMatch1.4.9
OR
djangoprojectdjangoMatch1.4.10
OR
djangoprojectdjangoMatch1.4.11
OR
djangoprojectdjangoMatch1.4.12
Node
djangoprojectdjangoMatch1.7beta1
OR
djangoprojectdjangoMatch1.7beta2
OR
djangoprojectdjangoMatch1.7beta3
OR
djangoprojectdjangoMatch1.7beta4
OR
djangoprojectdjangoMatch1.7rc1
OR
djangoprojectdjangoMatch1.7rc2
Node
djangoprojectdjangoMatch1.5
OR
djangoprojectdjangoMatch1.5alpha
OR
djangoprojectdjangoMatch1.5beta
OR
djangoprojectdjangoMatch1.5.1
OR
djangoprojectdjangoMatch1.5.2
OR
djangoprojectdjangoMatch1.5.3
OR
djangoprojectdjangoMatch1.5.4
OR
djangoprojectdjangoMatch1.5.5
OR
djangoprojectdjangoMatch1.5.6
OR
djangoprojectdjangoMatch1.5.7
OR
djangoprojectdjangoMatch1.5.8

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.3%