Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "12.04"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "14.04"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "16.04"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.10:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "16.10"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "24"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "25"
}
]
}
]
}{
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:djangoproject:django:1.8:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.1:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.2:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.3:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.4:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.5:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.6:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.7:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.8:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.9:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.10:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.11:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.12:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.13:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.14:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.8.15:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.10:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.10.1:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.10.2:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.1:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.2:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.3:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.4:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.5:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.6:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.7:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.8:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.9:*:*:*:*:*:*:*",
"cpe:2.3:a:djangoproject:django:1.9.10:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.8"
},
{
"last_affected": "1.8.1"
},
{
"last_affected": "1.8.2"
},
{
"last_affected": "1.8.3"
},
{
"last_affected": "1.8.4"
},
{
"last_affected": "1.8.5"
},
{
"last_affected": "1.8.6"
},
{
"last_affected": "1.8.7"
},
{
"last_affected": "1.8.8"
},
{
"last_affected": "1.8.9"
},
{
"last_affected": "1.8.10"
},
{
"last_affected": "1.8.11"
},
{
"last_affected": "1.8.12"
},
{
"last_affected": "1.8.13"
},
{
"last_affected": "1.8.14"
},
{
"last_affected": "1.8.15"
},
{
"last_affected": "1.10"
},
{
"last_affected": "1.10.1"
},
{
"last_affected": "1.10.2"
},
{
"last_affected": "1.9"
},
{
"last_affected": "1.9.1"
},
{
"last_affected": "1.9.2"
},
{
"last_affected": "1.9.3"
},
{
"last_affected": "1.9.4"
},
{
"last_affected": "1.9.5"
},
{
"last_affected": "1.9.6"
},
{
"last_affected": "1.9.7"
},
{
"last_affected": "1.9.8"
},
{
"last_affected": "1.9.9"
},
{
"last_affected": "1.9.10"
}
]
}