[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3678-1 python-django -- python-django

ID: oval:org.secpod.oval:def:602628Date: (C)2016-09-29   (M)2023-12-20
Class: PATCHFamily: unix




Sergey Bobrov discovered that cookie parsing in Django and Google Analytics interacted such a way that an attacker could set arbitrary cookies. This allows other malicious web sites to bypass the Cross-Site Request Forgery protections built into Django.

Platform:
Debian 8.x
Product:
python-django
Reference:
DSA-3678-1
CVE-2016-7401
CVE    1
CVE-2016-7401
CPE    2
cpe:/o:debian:debian_linux:8.x
cpe:/a:djangoproject:python-django

© SecPod Technologies