CVE-2011-4136

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-4136
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2011-4136.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2011-4136
Aliases
Downstream
Published
2011-10-19T10:55:03Z
Modified
2025-08-09T20:01:26Z
Summary
[none]
Details

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which allows remote attackers to modify a session by triggering use of a key that is equal to that session's identifier.

References

Affected packages