CVE-2015-5964: High severity django vulnerability
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cachedb.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.
Other sources
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cachedb.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5964?
CVE-2015-5964 has a medium severity rating as it can lead to denial of service through empty session creation.
How do I fix CVE-2015-5964?
To resolve CVE-2015-5964, upgrade Django to version 1.4.22 or 1.7.10 or later.
Which versions of Django are affected by CVE-2015-5964?
CVE-2015-5964 affects Django versions 1.4.x before 1.4.22 and 1.7.x before 1.7.10.
How does CVE-2015-5964 impact web applications?
CVE-2015-5964 allows attackers to cause denial of service by creating empty sessions, which can disrupt user sessions.
Is CVE-2015-5964 patched in later Django versions?
Yes, CVE-2015-5964 is patched in Django versions 1.4.22 and 1.7.10.