CVE-2016-7401
03.10.2016, 18:59
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
djangoproject | django | 𝑥 ≤ 1.8.14 |
djangoproject | django | 1.9.0 |
djangoproject | django | 1.9.1 |
djangoproject | django | 1.9.2 |
djangoproject | django | 1.9.3 |
djangoproject | django | 1.9.4 |
djangoproject | django | 1.9.5 |
djangoproject | django | 1.9.6 |
djangoproject | django | 1.9.7 |
djangoproject | django | 1.9.8 |
djangoproject | django | 1.9.9 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References