6.4
CVSSv2

CVE-2014-1418

Published: 16/05/2014 Updated: 07/01/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Django 1.4 prior to 1.4.13, 1.5 prior to 1.5.8, 1.6 prior to 1.6.5, and 1.7 prior to 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote malicious users to obtain sensitive information or poison the cache via a request from certain browsers.

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django 1.7

djangoproject django 1.4.12

djangoproject django 1.4.2

djangoproject django 1.4.4

djangoproject django 1.4

djangoproject django 1.4.1

djangoproject django 1.4.7

djangoproject django 1.4.8

djangoproject django 1.4.5

djangoproject django 1.4.6

djangoproject django 1.4.10

djangoproject django 1.4.11

djangoproject django 1.4.9

djangoproject django 1.5.7

djangoproject django 1.5.6

djangoproject django 1.5.3

djangoproject django 1.5.4

djangoproject django 1.5

djangoproject django 1.5.5

djangoproject django 1.5.1

djangoproject django 1.5.2

canonical ubuntu linux 12.04

canonical ubuntu linux 12.10

canonical ubuntu linux 10.04

canonical ubuntu linux 13.10

canonical ubuntu linux 14.04

djangoproject django 1.6

djangoproject django 1.6.4

djangoproject django 1.6.1

djangoproject django 1.6.2

djangoproject django 1.6.3

Vendor Advisories

Django applications could be made to expose sensitive information over the network ...
Several vulnerabilities were discovered in Django, a high-level Python web development framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-0472 Benjamin Bach discovered that Django incorrectly handled dotted Python paths when using the reverse() URL resolver function An attacker able ...
Django 14 before 1413, 15 before 158, 16 before 165, and 17 before 17b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers ...