CVE Vulnerabilities

CVE-2015-5964

Published: Aug 24, 2015 | Modified: Dec 24, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject 1.4 (including) 1.4 (including)
Django Djangoproject 1.4.1 (including) 1.4.1 (including)
Django Djangoproject 1.4.2 (including) 1.4.2 (including)
Django Djangoproject 1.4.4 (including) 1.4.4 (including)
Django Djangoproject 1.4.5 (including) 1.4.5 (including)
Django Djangoproject 1.4.6 (including) 1.4.6 (including)
Django Djangoproject 1.4.7 (including) 1.4.7 (including)
Django Djangoproject 1.4.8 (including) 1.4.8 (including)
Django Djangoproject 1.4.9 (including) 1.4.9 (including)
Django Djangoproject 1.4.10 (including) 1.4.10 (including)
Django Djangoproject 1.4.11 (including) 1.4.11 (including)
Django Djangoproject 1.4.12 (including) 1.4.12 (including)
Django Djangoproject 1.4.13 (including) 1.4.13 (including)
Django Djangoproject 1.4.14 (including) 1.4.14 (including)
Django Djangoproject 1.4.17 (including) 1.4.17 (including)
Django Djangoproject 1.4.19 (including) 1.4.19 (including)
Django Djangoproject 1.4.20 (including) 1.4.20 (including)
Django Djangoproject 1.4.21 (including) 1.4.21 (including)
Django Djangoproject 1.7-beta1 (including) 1.7-beta1 (including)
Django Djangoproject 1.7-beta2 (including) 1.7-beta2 (including)
Django Djangoproject 1.7-beta3 (including) 1.7-beta3 (including)
Django Djangoproject 1.7-beta4 (including) 1.7-beta4 (including)
Django Djangoproject 1.7-rc1 (including) 1.7-rc1 (including)
Django Djangoproject 1.7-rc2 (including) 1.7-rc2 (including)
Django Djangoproject 1.7-rc3 (including) 1.7-rc3 (including)
Django Djangoproject 1.7.1 (including) 1.7.1 (including)
Django Djangoproject 1.7.2 (including) 1.7.2 (including)
Django Djangoproject 1.7.3 (including) 1.7.3 (including)
Django Djangoproject 1.7.4 (including) 1.7.4 (including)
Django Djangoproject 1.7.5 (including) 1.7.5 (including)
Django Djangoproject 1.7.6 (including) 1.7.6 (including)
Django Djangoproject 1.7.7 (including) 1.7.7 (including)
Django Djangoproject 1.7.8 (including) 1.7.8 (including)
Django Djangoproject 1.7.9 (including) 1.7.9 (including)
Django Djangoproject 1.8-beta1 (including) 1.8-beta1 (including)
Django Djangoproject 1.8.0 (including) 1.8.0 (including)
Django Djangoproject 1.8.1 (including) 1.8.1 (including)
Django Djangoproject 1.8.2 (including) 1.8.2 (including)
Django Djangoproject 1.8.3 (including) 1.8.3 (including)

References