CVE Vulnerabilities

CVE-2015-5963

Published: Aug 24, 2015 | Modified: Oct 03, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consumption or session record removal) via a large number of requests to contrib.auth.views.logout, which triggers the creation of an empty session record.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject 1.4 (including) 1.4 (including)
Django Djangoproject 1.4.1 (including) 1.4.1 (including)
Django Djangoproject 1.4.2 (including) 1.4.2 (including)
Django Djangoproject 1.4.4 (including) 1.4.4 (including)
Django Djangoproject 1.4.5 (including) 1.4.5 (including)
Django Djangoproject 1.4.6 (including) 1.4.6 (including)
Django Djangoproject 1.4.7 (including) 1.4.7 (including)
Django Djangoproject 1.4.8 (including) 1.4.8 (including)
Django Djangoproject 1.4.9 (including) 1.4.9 (including)
Django Djangoproject 1.4.10 (including) 1.4.10 (including)
Django Djangoproject 1.4.11 (including) 1.4.11 (including)
Django Djangoproject 1.4.12 (including) 1.4.12 (including)
Django Djangoproject 1.4.13 (including) 1.4.13 (including)
Django Djangoproject 1.4.14 (including) 1.4.14 (including)
Django Djangoproject 1.4.17 (including) 1.4.17 (including)
Django Djangoproject 1.4.19 (including) 1.4.19 (including)
Django Djangoproject 1.4.20 (including) 1.4.20 (including)
Django Djangoproject 1.4.21 (including) 1.4.21 (including)
Django Djangoproject 1.7-beta1 (including) 1.7-beta1 (including)
Django Djangoproject 1.7-beta2 (including) 1.7-beta2 (including)
Django Djangoproject 1.7-beta3 (including) 1.7-beta3 (including)
Django Djangoproject 1.7-beta4 (including) 1.7-beta4 (including)
Django Djangoproject 1.7-rc1 (including) 1.7-rc1 (including)
Django Djangoproject 1.7-rc2 (including) 1.7-rc2 (including)
Django Djangoproject 1.7-rc3 (including) 1.7-rc3 (including)
Django Djangoproject 1.7.1 (including) 1.7.1 (including)
Django Djangoproject 1.7.2 (including) 1.7.2 (including)
Django Djangoproject 1.7.3 (including) 1.7.3 (including)
Django Djangoproject 1.7.4 (including) 1.7.4 (including)
Django Djangoproject 1.7.5 (including) 1.7.5 (including)
Django Djangoproject 1.7.6 (including) 1.7.6 (including)
Django Djangoproject 1.7.7 (including) 1.7.7 (including)
Django Djangoproject 1.7.8 (including) 1.7.8 (including)
Django Djangoproject 1.7.9 (including) 1.7.9 (including)
Django Djangoproject 1.8-beta1 (including) 1.8-beta1 (including)
Django Djangoproject 1.8.0 (including) 1.8.0 (including)
Django Djangoproject 1.8.1 (including) 1.8.1 (including)
Django Djangoproject 1.8.2 (including) 1.8.2 (including)
Django Djangoproject 1.8.3 (including) 1.8.3 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 RedHat python-django-0:1.6.11-3.el6ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 RedHat python-django-0:1.6.11-3.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat python-django-0:1.6.11-3.el7ost *
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 RedHat python-django-0:1.8.4-1.el7 *
Python-django Ubuntu devel *
Python-django Ubuntu precise *
Python-django Ubuntu trusty *
Python-django Ubuntu upstream *
Python-django Ubuntu vivid *

References