CVE Vulnerabilities

CVE-2015-5963

Published: Aug 24, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consumption or session record removal) via a large number of requests to contrib.auth.views.logout, which triggers the creation of an empty session record.

Affected Software

NameVendorStart VersionEnd Version
DjangoDjangoproject1.4 (including)1.4 (including)
DjangoDjangoproject1.4.1 (including)1.4.1 (including)
DjangoDjangoproject1.4.2 (including)1.4.2 (including)
DjangoDjangoproject1.4.4 (including)1.4.4 (including)
DjangoDjangoproject1.4.5 (including)1.4.5 (including)
DjangoDjangoproject1.4.6 (including)1.4.6 (including)
DjangoDjangoproject1.4.7 (including)1.4.7 (including)
DjangoDjangoproject1.4.8 (including)1.4.8 (including)
DjangoDjangoproject1.4.9 (including)1.4.9 (including)
DjangoDjangoproject1.4.10 (including)1.4.10 (including)
DjangoDjangoproject1.4.11 (including)1.4.11 (including)
DjangoDjangoproject1.4.12 (including)1.4.12 (including)
DjangoDjangoproject1.4.13 (including)1.4.13 (including)
DjangoDjangoproject1.4.14 (including)1.4.14 (including)
DjangoDjangoproject1.4.17 (including)1.4.17 (including)
DjangoDjangoproject1.4.19 (including)1.4.19 (including)
DjangoDjangoproject1.4.20 (including)1.4.20 (including)
DjangoDjangoproject1.4.21 (including)1.4.21 (including)
DjangoDjangoproject1.7-beta1 (including)1.7-beta1 (including)
DjangoDjangoproject1.7-beta2 (including)1.7-beta2 (including)
DjangoDjangoproject1.7-beta3 (including)1.7-beta3 (including)
DjangoDjangoproject1.7-beta4 (including)1.7-beta4 (including)
DjangoDjangoproject1.7-rc1 (including)1.7-rc1 (including)
DjangoDjangoproject1.7-rc2 (including)1.7-rc2 (including)
DjangoDjangoproject1.7-rc3 (including)1.7-rc3 (including)
DjangoDjangoproject1.7.1 (including)1.7.1 (including)
DjangoDjangoproject1.7.2 (including)1.7.2 (including)
DjangoDjangoproject1.7.3 (including)1.7.3 (including)
DjangoDjangoproject1.7.4 (including)1.7.4 (including)
DjangoDjangoproject1.7.5 (including)1.7.5 (including)
DjangoDjangoproject1.7.6 (including)1.7.6 (including)
DjangoDjangoproject1.7.7 (including)1.7.7 (including)
DjangoDjangoproject1.7.8 (including)1.7.8 (including)
DjangoDjangoproject1.7.9 (including)1.7.9 (including)
DjangoDjangoproject1.8-beta1 (including)1.8-beta1 (including)
DjangoDjangoproject1.8.0 (including)1.8.0 (including)
DjangoDjangoproject1.8.1 (including)1.8.1 (including)
DjangoDjangoproject1.8.2 (including)1.8.2 (including)
DjangoDjangoproject1.8.3 (including)1.8.3 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatpython-django-0:1.6.11-3.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatpython-django-0:1.6.11-3.el7ost*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatpython-django-0:1.6.11-3.el7ost*
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7RedHatpython-django-0:1.8.4-1.el7*
Python-djangoUbuntudevel*
Python-djangoUbuntuesm-infra-legacy/trusty*
Python-djangoUbuntuprecise*
Python-djangoUbuntutrusty*
Python-djangoUbuntutrusty/esm*
Python-djangoUbuntuupstream*
Python-djangoUbuntuvivid*

References