CVE-2014-0482

EUVD-2014-0014
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
opensuseopensuse
12.3
opensuseopensuse
13.1
djangoprojectdjango
1.6
djangoprojectdjango
1.6:beta1
djangoprojectdjango
1.6:beta2
djangoprojectdjango
1.6:beta3
djangoprojectdjango
1.6:beta4
djangoprojectdjango
1.6.1
djangoprojectdjango
1.6.2
djangoprojectdjango
1.6.3
djangoprojectdjango
1.6.4
djangoprojectdjango
1.6.5
djangoprojectdjango
𝑥
≤ 1.4.13
djangoprojectdjango
1.4
djangoprojectdjango
1.4.1
djangoprojectdjango
1.4.2
djangoprojectdjango
1.4.4
djangoprojectdjango
1.4.5
djangoprojectdjango
1.4.6
djangoprojectdjango
1.4.7
djangoprojectdjango
1.4.8
djangoprojectdjango
1.4.9
djangoprojectdjango
1.4.10
djangoprojectdjango
1.4.11
djangoprojectdjango
1.4.12
djangoprojectdjango
1.7:beta1
djangoprojectdjango
1.7:beta2
djangoprojectdjango
1.7:beta3
djangoprojectdjango
1.7:beta4
djangoprojectdjango
1.7:rc1
djangoprojectdjango
1.7:rc2
djangoprojectdjango
1.5
djangoprojectdjango
1.5:alpha
djangoprojectdjango
1.5:beta
djangoprojectdjango
1.5.1
djangoprojectdjango
1.5.2
djangoprojectdjango
1.5.3
djangoprojectdjango
1.5.4
djangoprojectdjango
1.5.5
djangoprojectdjango
1.5.6
djangoprojectdjango
1.5.7
djangoprojectdjango
1.5.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-django
bookworm
3:3.2.19-1+deb12u1
fixed
bookworm (security)
3:3.2.19-1+deb12u1
fixed
bullseye
2:2.2.28-1~deb11u2
fixed
bullseye (security)
2:2.2.28-1~deb11u2
fixed
sid
3:4.2.16-1
fixed
trixie
3:4.2.16-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-django
lucid
Fixed 1.1.1-2ubuntu1.13
released
precise
Fixed 1.3.1-4ubuntu1.12
released
trusty
Fixed 1.6.1-2ubuntu0.4
released