QID 981047
QID 981047: Python (pip) Security Update for django (GHSA-h95j-h2rv-qrg4)
The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers to trigger unauthenticated forged requests via vectors involving a DNS CNAME record and a web page containing JavaScript code.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h95j-h2rv-qrg4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-h95j-h2rv-qrg4 -
github.com/advisories/GHSA-h95j-h2rv-qrg4
CVEs related to QID 981047
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h95j-h2rv-qrg4 | django |
|