CVE-2016-7401
03.10.2016, 18:59
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| djangoproject | django | 𝑥 ≤ 1.8.14 |
| djangoproject | django | 1.9.0 |
| djangoproject | django | 1.9.1 |
| djangoproject | django | 1.9.2 |
| djangoproject | django | 1.9.3 |
| djangoproject | django | 1.9.4 |
| djangoproject | django | 1.9.5 |
| djangoproject | django | 1.9.6 |
| djangoproject | django | 1.9.7 |
| djangoproject | django | 1.9.8 |
| djangoproject | django | 1.9.9 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References