DSA-3338-1 python-django -- python-djangoID: oval:org.secpod.oval:def:602197 | Date: (C)2015-08-28 (M)2022-09-22 |
Class: PATCH | Family: unix |
Lin Hua Cheng discovered that a session could be created when anonymously accessing the django.contrib.auth.views.logout view. This could allow remote attackers to saturate the session store or cause other users" session records to be evicted. Additionally the contrib.sessions.backends.base.SessionBase.flush and cache_db.SessionStore.flush methods have been modified to avoid creating a new empty session as well.
Platform: |
Debian 8.x |
Debian 7.x |