icon

We found results for “

CVE-2016-7401

Good to know:

icon
icon

Date: October 3, 2016

The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Security Features

CWE-254

Top Fix

icon

Upgrade Version

Upgrade to version Django - 1.11.15;Django - 2.0.3;Django - 2.0.8;Django - 1.11.9;Django - 1.8;Django - 1.9.10;Django - 1.11.15;Django - 1.8.15;Django - 2.0.8;django - 1.8.16;django - 1.7.11;django - 1.9.12;acosf/archersys - 1.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): HIGH
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): LOW
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us