Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2014-0482

Published: 26 August 2014

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

Priority

Medium

Status

Package Release Status
python-django
Launchpad, Ubuntu, Debian
lucid
Released (1.1.1-2ubuntu1.13)
precise
Released (1.3.1-4ubuntu1.12)
trusty
Released (1.6.1-2ubuntu0.4)
upstream
Released (1.6.6-1)
Patches:
upstream: https://github.com/django/django/commit/c9e3b9949cd55f090591fbdc4a114fcb8368b6d9
upstream: https://github.com/django/django/commit/0268b855f9eab3377f2821164ef3e66037789e09