Back

MEDIUM

django: incorrect session flushing in the cached_db backend

Published Jun 2, 2015

Description

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

Affected products

Remediation

Red Hat statement

Not vulnerable. The 1.8 version of Django is not shipped in any Red Hat product.

Metrics

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2015
Updated Aug 6, 2024
Reserved May 13, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 20, 2015
GHSA-6WGP-FWFM-MXP3