CVE Vulnerabilities

CVE-2015-5143

Published: Jul 14, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.

Affected Software

NameVendorStart VersionEnd Version
DjangoDjangoproject1.4.20 (including)1.4.20 (including)
DjangoDjangoproject1.5 (including)1.5 (including)
DjangoDjangoproject1.5-alpha (including)1.5-alpha (including)
DjangoDjangoproject1.5-beta (including)1.5-beta (including)
DjangoDjangoproject1.5.1 (including)1.5.1 (including)
DjangoDjangoproject1.5.2 (including)1.5.2 (including)
DjangoDjangoproject1.5.3 (including)1.5.3 (including)
DjangoDjangoproject1.5.4 (including)1.5.4 (including)
DjangoDjangoproject1.5.5 (including)1.5.5 (including)
DjangoDjangoproject1.5.6 (including)1.5.6 (including)
DjangoDjangoproject1.5.7 (including)1.5.7 (including)
DjangoDjangoproject1.5.8 (including)1.5.8 (including)
DjangoDjangoproject1.5.9 (including)1.5.9 (including)
DjangoDjangoproject1.5.10 (including)1.5.10 (including)
DjangoDjangoproject1.5.11 (including)1.5.11 (including)
DjangoDjangoproject1.5.12 (including)1.5.12 (including)
DjangoDjangoproject1.6 (including)1.6 (including)
DjangoDjangoproject1.6-beta1 (including)1.6-beta1 (including)
DjangoDjangoproject1.6-beta2 (including)1.6-beta2 (including)
DjangoDjangoproject1.6-beta3 (including)1.6-beta3 (including)
DjangoDjangoproject1.6-beta4 (including)1.6-beta4 (including)
DjangoDjangoproject1.6.1 (including)1.6.1 (including)
DjangoDjangoproject1.6.2 (including)1.6.2 (including)
DjangoDjangoproject1.6.3 (including)1.6.3 (including)
DjangoDjangoproject1.6.4 (including)1.6.4 (including)
DjangoDjangoproject1.6.5 (including)1.6.5 (including)
DjangoDjangoproject1.6.6 (including)1.6.6 (including)
DjangoDjangoproject1.6.7 (including)1.6.7 (including)
DjangoDjangoproject1.6.8 (including)1.6.8 (including)
DjangoDjangoproject1.6.9 (including)1.6.9 (including)
DjangoDjangoproject1.6.10 (including)1.6.10 (including)
DjangoDjangoproject1.7-beta1 (including)1.7-beta1 (including)
DjangoDjangoproject1.7-beta2 (including)1.7-beta2 (including)
DjangoDjangoproject1.7-beta3 (including)1.7-beta3 (including)
DjangoDjangoproject1.7-beta4 (including)1.7-beta4 (including)
DjangoDjangoproject1.7-rc1 (including)1.7-rc1 (including)
DjangoDjangoproject1.7-rc2 (including)1.7-rc2 (including)
DjangoDjangoproject1.7-rc3 (including)1.7-rc3 (including)
DjangoDjangoproject1.7.1 (including)1.7.1 (including)
DjangoDjangoproject1.7.2 (including)1.7.2 (including)
DjangoDjangoproject1.7.3 (including)1.7.3 (including)
DjangoDjangoproject1.7.4 (including)1.7.4 (including)
DjangoDjangoproject1.7.5 (including)1.7.5 (including)
DjangoDjangoproject1.7.6 (including)1.7.6 (including)
DjangoDjangoproject1.7.7 (including)1.7.7 (including)
DjangoDjangoproject1.7.8 (including)1.7.8 (including)
DjangoDjangoproject1.7.9 (including)1.7.9 (including)
DjangoDjangoproject1.8.0 (including)1.8.0 (including)
DjangoDjangoproject1.8.1 (including)1.8.1 (including)
DjangoDjangoproject1.8.2 (including)1.8.2 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatpython-django-0:1.6.11-1.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatpython-django-0:1.6.11-2.el7ost*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatpython-django-0:1.6.11-2.el7ost*
Python-djangoUbuntudevel*
Python-djangoUbuntuesm-infra-legacy/trusty*
Python-djangoUbuntuprecise*
Python-djangoUbuntutrusty*
Python-djangoUbuntutrusty/esm*
Python-djangoUbuntuupstream*
Python-djangoUbuntuutopic*
Python-djangoUbuntuvivid*

References