Django Vulnerable to Cache Poisoning
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Sep 16, 2024
Description
Published by the National Vulnerability Database
Oct 19, 2011
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jan 16, 2024
Last updated
Sep 16, 2024
Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poisoning attacks via a crafted request.
References