CVE-2015-3982

Django 1.8.x < 1.8.2 - Session Hijacking via Empty Session Key

Title source: llm
STIX 2.1

Description

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.djangoproject.com/weblog/2015/may/20/security-release/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74960

Scores

EPSS 0.0175
EPSS Percentile 75.5%

Details

Status published
Products (3)
djangoproject/django 1.8.0
djangoproject/django 1.8.1
pypi/Django 1.8a1 - 1.8.2PyPI
Published Jun 02, 2015
Tracked Since Feb 18, 2026