CVE Vulnerabilities

CVE-2014-0473

Published: Apr 23, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

Affected Software

NameVendorStart VersionEnd Version
DjangoDjangoproject1.5 (including)1.5 (including)
DjangoDjangoproject1.5.1 (including)1.5.1 (including)
DjangoDjangoproject1.5.2 (including)1.5.2 (including)
DjangoDjangoproject1.5.3 (including)1.5.3 (including)
DjangoDjangoproject1.5.4 (including)1.5.4 (including)
DjangoDjangoproject1.5.5 (including)1.5.5 (including)
OpenStack 3 for RHEL 6RedHatDjango14-0:1.4.11-1.el6ost*
OpenStack 4 for RHEL 6RedHatDjango14-0:1.4.11-1.el6ost*
Python-djangoUbuntuesm-infra-legacy/trusty*
Python-djangoUbuntulucid*
Python-djangoUbuntuprecise*
Python-djangoUbuntuquantal*
Python-djangoUbuntusaucy*
Python-djangoUbuntutrusty*
Python-djangoUbuntutrusty/esm*
Python-djangoUbuntuupstream*

References