CVE-2014-1418
Publication date 14 May 2014
Last updated 24 July 2024
Ubuntu priority
Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | 14.04 LTS trusty |
Fixed 1.6.1-2ubuntu0.3
|
References
Related Ubuntu Security Notices (USN)
- USN-2212-1
- Django vulnerabilities
- 15 May 2014