6

CVE-2014-0482

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

Data is provided by the National Vulnerability Database (NVD)
OpensuseOpensuse Version12.3
OpensuseOpensuse Version13.1
DjangoprojectDjango Version1.6 Update-
DjangoprojectDjango Version1.6 Updatebeta1
DjangoprojectDjango Version1.6 Updatebeta2
DjangoprojectDjango Version1.6 Updatebeta3
DjangoprojectDjango Version1.6 Updatebeta4
DjangoprojectDjango Version1.6.1
DjangoprojectDjango Version1.6.2
DjangoprojectDjango Version1.6.3
DjangoprojectDjango Version1.6.4
DjangoprojectDjango Version1.6.5
DjangoprojectDjango Version <= 1.4.13
DjangoprojectDjango Version1.4
DjangoprojectDjango Version1.4.1
DjangoprojectDjango Version1.4.2
DjangoprojectDjango Version1.4.4
DjangoprojectDjango Version1.4.5
DjangoprojectDjango Version1.4.6
DjangoprojectDjango Version1.4.7
DjangoprojectDjango Version1.4.8
DjangoprojectDjango Version1.4.9
DjangoprojectDjango Version1.4.10
DjangoprojectDjango Version1.4.11
DjangoprojectDjango Version1.4.12
DjangoprojectDjango Version1.7 Updatebeta1
DjangoprojectDjango Version1.7 Updatebeta2
DjangoprojectDjango Version1.7 Updatebeta3
DjangoprojectDjango Version1.7 Updatebeta4
DjangoprojectDjango Version1.7 Updaterc1
DjangoprojectDjango Version1.7 Updaterc2
DjangoprojectDjango Version1.5
DjangoprojectDjango Version1.5 Updatealpha
DjangoprojectDjango Version1.5 Updatebeta
DjangoprojectDjango Version1.5.1
DjangoprojectDjango Version1.5.2
DjangoprojectDjango Version1.5.3
DjangoprojectDjango Version1.5.4
DjangoprojectDjango Version1.5.5
DjangoprojectDjango Version1.5.6
DjangoprojectDjango Version1.5.7
DjangoprojectDjango Version1.5.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.71% 0.713
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.