CVE-2015-0219
Published Jan 16, 2015
Last updated 8 years ago
Overview
- Description
- Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-17
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E636F6CA-1979-43DA-A12F-23EC009B4A65", "versionEndIncluding": "1.4.17" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5463AB51-6088-473A-BB54-BB78ACFC6DCA" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0CC369A0-0092-450D-91E9-13C7AF7EBC16" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B6B7974-ABEF-4E0C-8503-6E9C22D28C78" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55460F1D-661B-465C-8A22-E4E6DA2834B3" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9FD4FB46-3A98-4B9B-A241-C39E2C2A0FEC" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF87FDAB-51A2-41C4-A4C4-5180B0230C3F" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80E8431B-FEA1-4D94-B367-56E8678C3CD3" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81E7779A-EDB9-4871-8D7C-63C5A7C7A0DB" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABB56113-5E66-4EE9-B551-FD40C2FE307B" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.6.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2985241-279F-46AC-8BBF-DF2F439FE720" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72653EB4-CE19-42FC-9C99-5CB391DABE7E" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06513AE1-11E4-4A9C-BDA4-D0511A9DCFC8" }, { "criteria": "cpe:2.3:a:djangoproject:django:1.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6004EA17-A2B4-4E4C-A738-210FCAC2CA32" } ], "operator": "OR" } ] } ]