CVE-2016-9014

Description

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.045

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-9013,CVE-2016-9014 are fixed in Python-django 1.10.3Windows
Vulnerabilities CVE-2016-9013,CVE-2016-9014 are fixed in Python-django 1.8.16Windows
Vulnerabilities CVE-2016-9013,CVE-2016-9014 are fixed in Python-django 1.9.11Windows
Vulnerabilities CVE-2016-9013,CVE-2016-9014 are fixed in Python-django for linux 1.10.3Linux
Vulnerabilities CVE-2016-9013,CVE-2016-9014 are fixed in Python-django for linux 1.8.16Linux
Vulnerabilities CVE-2016-9013,CVE-2016-9014 are fixed in Python-django for linux 1.9.11Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234