QID 996726
Date Published: 2024-01-17
QID 996726: Python (Pip) Security Update for django (GHSA-rm2j-x595-q9cj)
Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poisoning attacks via a crafted request.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rm2j-x595-q9cj for updates and patch information.
Vendor References
- GHSA-rm2j-x595-q9cj -
github.com/advisories/GHSA-rm2j-x595-q9cj
CVEs related to QID 996726
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rm2j-x595-q9cj | django |
|