QID 981068
QID 981068: Python (pip) Security Update for django (GHSA-h582-2pch-3xv3)
The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h582-2pch-3xv3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-h582-2pch-3xv3 -
github.com/advisories/GHSA-h582-2pch-3xv3
CVEs related to QID 981068
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h582-2pch-3xv3 | django |
|