CVE-2011-4139: Input Validation
Published Oct 19, 2011
·Updated
Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poisoning attacks via a crafted request.
Affected Software
24 affected componentsFixes available
pip/Django>=1.3<1.3.1
1.3.1
pip/django<1.2.7
1.2.7
djangoproject Django<=1.2.6
djangoproject Django=1.2.5
djangoproject Django=0.95
djangoproject Django=1.0
djangoproject Django=1.3
djangoproject Django=1.1.2
djangoproject Django=1.0.1
djangoproject Django=1.1
djangoproject Django=1.2.1
djangoproject Django=1.2.4
djangoproject Django=0.91
djangoproject Django=1.0.2
djangoproject Django=1.2.3
djangoproject Django=1.3-alpha1
djangoproject Django=1.1.3
djangoproject Django=1.2.1-2
djangoproject Django=1.2
djangoproject Django=0.95.1
djangoproject Django=0.96
djangoproject Django=1.3-alpha2
djangoproject Django=1.1.0
djangoproject Django=1.2.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Oct 19, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
May 14, 2022
Advisory Published
via GitHub·03:49 AM
Frequently Asked Questions
1
What is the severity of CVE-2011-4139?
CVE-2011-4139 is classified as a medium severity vulnerability due to its potential for cache poisoning attacks.
2
How do I fix CVE-2011-4139?
To fix CVE-2011-4139, upgrade Django to version 1.2.7 or 1.3.1 or later.
3
Which versions of Django are affected by CVE-2011-4139?
Versions of Django prior to 1.2.7 and those in the 1.3.x series prior to 1.3.1 are affected by CVE-2011-4139.
4
What type of attack is possible with CVE-2011-4139?
CVE-2011-4139 allows remote attackers to conduct cache poisoning attacks via crafted requests.
5
Is it safe to use Django versions below 1.2.7 or 1.3.1 after the CVE-2011-4139 disclosure?
No, using Django versions below 1.2.7 or 1.3.1 poses a security risk due to the vulnerability described in CVE-2011-4139.