CVE-2011-4136

Source
https://cve.org/CVERecord?id=CVE-2011-4136
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2011-4136.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2011-4136
Aliases
Downstream
Withdrawn
2026-01-27T04:12:55.712930Z
Published
2011-10-19T10:55:03Z
Modified
2026-01-27T04:12:55.712930Z
Summary
[none]
Details

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.

References

Affected packages