CVE-2014-0482

Description

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.711

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-0480,CVE-2014-0481,CVE-2014-0482,CVE-2014-0483 are fixed in Python-django 1.4.14Windows
Vulnerabilities CVE-2014-0480,CVE-2014-0481,CVE-2014-0482,CVE-2014-0483 are fixed in Python-django 1.5.9Windows
Vulnerabilities CVE-2014-0480,CVE-2014-0481,CVE-2014-0482,CVE-2014-0483 are fixed in Python-django 1.6.6Windows
Vulnerabilities CVE-2014-0480,CVE-2014-0481,CVE-2014-0482,CVE-2014-0483 are fixed in Python-django for linux 1.4.14Linux
Vulnerabilities CVE-2014-0480,CVE-2014-0481,CVE-2014-0482,CVE-2014-0483 are fixed in Python-django for linux 1.5.9Linux
Vulnerabilities CVE-2014-0480,CVE-2014-0481,CVE-2014-0482,CVE-2014-0483 are fixed in Python-django for linux 1.6.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234