CVE-2014-0473
Publication date 22 April 2014
Last updated 24 July 2024
Ubuntu priority
The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | 14.04 LTS trusty |
Fixed 1.6.1-2ubuntu0.1
|
References
Related Ubuntu Security Notices (USN)
- USN-2169-1
- Django vulnerabilities
- 22 April 2014