Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11801
HistoryJan 15, 2019 - 9:07 a.m.

Denial Of Service (DoS) Session Store Consumption Or Session Record Removal

2019-01-1509:07:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.024 Low

EPSS

Percentile

89.9%

Django is vulnerable to denial of service through session store consumption or session record removal. This is caused in contrib.sessions.middleware.SessionMiddleware when a large number of requests are made to contrib.auth.views.logout, triggering the creation of empty session records, using up the store.