Django Multiple Security Vulnerabilities
BID:49573
Info
Django Multiple Security Vulnerabilities
| Bugtraq ID: | 49573 |
| Class: | Unknown |
| CVE: |
CVE-2011-4136 CVE-2011-4137 CVE-2011-4138 CVE-2011-4139 CVE-2011-4140 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2011 12:00AM |
| Updated: | Apr 13 2015 09:17PM |
| Credit: | Paul McMillan |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Djangoproject Django 1.2.5 Djangoproject Django 1.2.4 Djangoproject Django 1.2.2 Djangoproject Django 1.3 Beta 1 Djangoproject Django 1.2 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Djangoproject Django 1.3.1 Djangoproject Django 1.2.7 |
Discussion
Django Multiple Security Vulnerabilities
Django is prone to multiple security vulnerabilities including a security-bypass vulnerability, a denial-of-service vulnerability, an information-disclosure vulnerability, and a cache-poisoning vulnerability.
An attacker may leverage these issues to obtain potentially sensitive information, manipulate session data, bypass certain security restrictions, and conduct cache-poisoning attacks.
Django 1.2.x prior to 1.2.7 are vulnerable.
Django is prone to multiple security vulnerabilities including a security-bypass vulnerability, a denial-of-service vulnerability, an information-disclosure vulnerability, and a cache-poisoning vulnerability.
An attacker may leverage these issues to obtain potentially sensitive information, manipulate session data, bypass certain security restrictions, and conduct cache-poisoning attacks.
Django 1.2.x prior to 1.2.7 are vulnerable.
Exploit / POC
Django Multiple Security Vulnerabilities
An attacker can use a browser to exploit these issues.
An attacker can use a browser to exploit these issues.
Solution / Fix
Django Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Django Multiple Security Vulnerabilities
References:
References:
- Django 1.2.7 released (Django)
- Django Homepage (Django)
- Security releases issued (Django)