GHSA-x38m-486c-2wr9

Suggest an improvement
Source
https://github.com/advisories/GHSA-x38m-486c-2wr9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x38m-486c-2wr9/GHSA-x38m-486c-2wr9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x38m-486c-2wr9
Aliases
Published
2022-05-17T03:16:12Z
Modified
2024-09-18T20:08:13.320276Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 6.6 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Denial-of-service possibility in logout() view by filling session store
Details

The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.

References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.7
Fixed
1.7.10

Affected versions

1.*

1.7
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.4
Fixed
1.4.22

Affected versions

1.*

1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.18
1.4.19
1.4.20
1.4.21