CVE-2011-0696
Publication date 14 February 2011
Last updated 24 July 2024
Ubuntu priority
Description
Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged AJAX requests that leverage a "combination of browser plugins and redirects," a related issue to CVE-2011-0447.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | ||
Patch details
Package | Patch details |
---|---|
python-django |
References
Related Ubuntu Security Notices (USN)
- USN-1066-1
- Django vulnerabilities
- 17 February 2011