CVE-2015-3982
Publication date 20 May 2015
Last updated 24 July 2024
Ubuntu priority
Description
The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| python-django | ||
| 14.04 LTS trusty |
Not affected
|
|