CVE-2011-0696
Publication date 14 February 2011
Last updated 24 July 2024
Ubuntu priority
Description
Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged AJAX requests that leverage a "combination of browser plugins and redirects," a related issue to CVE-2011-0447.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| python-django | ||
Patch details
| Package | Patch details |
|---|---|
| python-django |
References
Related Ubuntu Security Notices (USN)
- USN-1066-1
- Django vulnerabilities
- 17 February 2011