CVE-2014-1418: High severity djangoproject Django vulnerability
Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1418?
CVE-2014-1418 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2014-1418?
To fix CVE-2014-1418, you should upgrade Django to version 1.4.13, 1.5.8, 1.6.5, or 1.7b4 or later.
What products are affected by CVE-2014-1418?
CVE-2014-1418 affects Django versions prior to 1.4.13, 1.5.8, 1.6.5, and 1.7b4.
What type of attacks can exploit CVE-2014-1418?
CVE-2014-1418 can be exploited by attackers to obtain sensitive information or poison the cache.
Is there a workaround for CVE-2014-1418?
There is no documented workaround for CVE-2014-1418; updating to the patched versions is recommended.