CVE-2014-0482
Publication date 26 August 2014
Last updated 24 July 2024
Ubuntu priority
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | 14.04 LTS trusty |
Fixed 1.6.1-2ubuntu0.4
|
References
Related Ubuntu Security Notices (USN)
- USN-2347-1
- Django vulnerabilities
- 16 September 2014