CVE-2015-3982
Django 1.8.x < 1.8.2 - Session Hijacking via Empty Session Key
Title source: llmDescription
The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.djangoproject.com/weblog/2015/may/20/security-release/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/74960
Scores
EPSS
0.0175
EPSS Percentile
75.5%
Details
Status
published
Products (3)
djangoproject/django
1.8.0
djangoproject/django
1.8.1
pypi/Django
1.8a1 - 1.8.2PyPI
Published
Jun 02, 2015
Tracked Since
Feb 18, 2026