CVE-2015-0219
Publication date 13 January 2015
Last updated 24 July 2024
Ubuntu priority
Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | ||
14.04 LTS trusty |
Fixed 1.6.1-2ubuntu0.6
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2469-1
- Django vulnerabilities
- 13 January 2015