5

CVE-2015-0219

Exploit

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.

Data is provided by the National Vulnerability Database (NVD)
DjangoprojectDjango Version <= 1.4.17
DjangoprojectDjango Version1.6
DjangoprojectDjango Version1.6.1
DjangoprojectDjango Version1.6.2
DjangoprojectDjango Version1.6.3
DjangoprojectDjango Version1.6.4
DjangoprojectDjango Version1.6.5
DjangoprojectDjango Version1.6.6
DjangoprojectDjango Version1.6.7
DjangoprojectDjango Version1.6.8
DjangoprojectDjango Version1.6.9
DjangoprojectDjango Version1.7
DjangoprojectDjango Version1.7.1
DjangoprojectDjango Version1.7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.72% 0.869
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N