CVE-2011-4139
Publication date 19 October 2011
Last updated 24 July 2024
Ubuntu priority
Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poisoning attacks via a crafted request.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | ||
Patch details
Package | Patch details |
---|---|
python-django |
References
Related Ubuntu Security Notices (USN)
- USN-1297-1
- Django vulnerabilities
- 9 December 2011