CVE Vulnerabilities

CVE-2015-5143

Published: Jul 14, 2015 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject 1.4.20 (including) 1.4.20 (including)
Django Djangoproject 1.5 (including) 1.5 (including)
Django Djangoproject 1.5-alpha (including) 1.5-alpha (including)
Django Djangoproject 1.5-beta (including) 1.5-beta (including)
Django Djangoproject 1.5.1 (including) 1.5.1 (including)
Django Djangoproject 1.5.2 (including) 1.5.2 (including)
Django Djangoproject 1.5.3 (including) 1.5.3 (including)
Django Djangoproject 1.5.4 (including) 1.5.4 (including)
Django Djangoproject 1.5.5 (including) 1.5.5 (including)
Django Djangoproject 1.5.6 (including) 1.5.6 (including)
Django Djangoproject 1.5.7 (including) 1.5.7 (including)
Django Djangoproject 1.5.8 (including) 1.5.8 (including)
Django Djangoproject 1.5.9 (including) 1.5.9 (including)
Django Djangoproject 1.5.10 (including) 1.5.10 (including)
Django Djangoproject 1.5.11 (including) 1.5.11 (including)
Django Djangoproject 1.5.12 (including) 1.5.12 (including)
Django Djangoproject 1.6 (including) 1.6 (including)
Django Djangoproject 1.6-beta1 (including) 1.6-beta1 (including)
Django Djangoproject 1.6-beta2 (including) 1.6-beta2 (including)
Django Djangoproject 1.6-beta3 (including) 1.6-beta3 (including)
Django Djangoproject 1.6-beta4 (including) 1.6-beta4 (including)
Django Djangoproject 1.6.1 (including) 1.6.1 (including)
Django Djangoproject 1.6.2 (including) 1.6.2 (including)
Django Djangoproject 1.6.3 (including) 1.6.3 (including)
Django Djangoproject 1.6.4 (including) 1.6.4 (including)
Django Djangoproject 1.6.5 (including) 1.6.5 (including)
Django Djangoproject 1.6.6 (including) 1.6.6 (including)
Django Djangoproject 1.6.7 (including) 1.6.7 (including)
Django Djangoproject 1.6.8 (including) 1.6.8 (including)
Django Djangoproject 1.6.9 (including) 1.6.9 (including)
Django Djangoproject 1.6.10 (including) 1.6.10 (including)
Django Djangoproject 1.7-beta1 (including) 1.7-beta1 (including)
Django Djangoproject 1.7-beta2 (including) 1.7-beta2 (including)
Django Djangoproject 1.7-beta3 (including) 1.7-beta3 (including)
Django Djangoproject 1.7-beta4 (including) 1.7-beta4 (including)
Django Djangoproject 1.7-rc1 (including) 1.7-rc1 (including)
Django Djangoproject 1.7-rc2 (including) 1.7-rc2 (including)
Django Djangoproject 1.7-rc3 (including) 1.7-rc3 (including)
Django Djangoproject 1.7.1 (including) 1.7.1 (including)
Django Djangoproject 1.7.2 (including) 1.7.2 (including)
Django Djangoproject 1.7.3 (including) 1.7.3 (including)
Django Djangoproject 1.7.4 (including) 1.7.4 (including)
Django Djangoproject 1.7.5 (including) 1.7.5 (including)
Django Djangoproject 1.7.6 (including) 1.7.6 (including)
Django Djangoproject 1.7.7 (including) 1.7.7 (including)
Django Djangoproject 1.7.8 (including) 1.7.8 (including)
Django Djangoproject 1.7.9 (including) 1.7.9 (including)
Django Djangoproject 1.8.0 (including) 1.8.0 (including)
Django Djangoproject 1.8.1 (including) 1.8.1 (including)
Django Djangoproject 1.8.2 (including) 1.8.2 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 RedHat python-django-0:1.6.11-1.el6ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 RedHat python-django-0:1.6.11-2.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat python-django-0:1.6.11-2.el7ost *
Python-django Ubuntu devel *
Python-django Ubuntu precise *
Python-django Ubuntu trusty *
Python-django Ubuntu upstream *
Python-django Ubuntu utopic *
Python-django Ubuntu vivid *

References