QID 980796
QID 980796: Python (pip) Security Update for django (GHSA-x88j-93vc-wpmp)
django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x88j-93vc-wpmp for updates pertaining to this vulnerability.
Vendor References
- GHSA-x88j-93vc-wpmp -
github.com/advisories/GHSA-x88j-93vc-wpmp
CVEs related to QID 980796
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x88j-93vc-wpmp | django |
|