CVE-2011-4139
Publication date 19 October 2011
Last updated 24 July 2024
Ubuntu priority
Description
Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poisoning attacks via a crafted request.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| python-django | ||
Patch details
| Package | Patch details | 
|---|---|
| python-django | 
References
Related Ubuntu Security Notices (USN)
- USN-1297-1
- Django vulnerabilities
- 9 December 2011