CVE-2014-0482

Published: 26 August 2014

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

Priority

Medium

Status

Package Release Status
python-django
Launchpad, Ubuntu, Debian
Upstream
Released (1.6.6-1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (1.6.1-2ubuntu0.4)
Patches:
Upstream: https://github.com/django/django/commit/c9e3b9949cd55f090591fbdc4a114fcb8368b6d9 (1.4)
Upstream: https://github.com/django/django/commit/0268b855f9eab3377f2821164ef3e66037789e09 (1.6)