CVE-2015-5964

Aliases:GHSA-x38m-486c-2wr9PYSEC-2015-23
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 24 Aug 2015, 14:00
Last modified:06 Aug 2024, 07:06

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
4.69% LOW
5% probability +0.33%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Aug 2015, 14:00
Published
Vulnerability first disclosed
06 Aug 2024, 07:06
Last Modified
Vulnerability information updated

Description

The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 4.69% Percentile: 90%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.04

  • djangoprojectdjango

    1.4 | 1.4.1 | 1.4.2 | 1.4.4 | 1.4.5 | 1.4.6 | 1.4.7 | 1.4.8 | 1.4.9 | 1.4.10 | 1.4.11 | 1.4.12 | 1.4.13 | 1.4.14 | 1.4.17 | 1.4.19 | 1.4.20 | 1.4.21 | 1.7:beta1 | 1.7:beta2 | 1.7:beta3 | 1.7:beta4 | 1.7:rc1 | 1.7:rc2 | 1.7:rc3 | 1.7.1 | 1.7.2 | 1.7.3 | 1.7.4 | 1.7.5 | 1.7.6 | 1.7.7 | 1.7.8 | 1.7.9 | 1.8:beta1 | 1.8.0 | 1.8.1 | 1.8.2 | 1.8.3

  • UnknownSolaris

    11.3

  • PyPIdjango

    ≥ 1.7, < 1.7.10 | ≥ 1.4, < 1.4.22

References (20)