Bugzilla – Bug 874955
VUL-0: CVE-2014-0473: python-django: caching of anonymous pages could reveal CSRF token
Last modified: 2015-02-19 01:49:25 UTC
Via rh#1090592: Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0473 to the following vulnerability: Name: CVE-2014-0473 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0473 Assigned: 20131219 Reference: https://www.djangoproject.com/weblog/2014/apr/21/security/ The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users. References: https://bugzilla.redhat.com/show_bug.cgi?id=1090592 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0473 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0473
bugbot adjusting priority
Issue is handled in SWAMP 57105
Reassigning to security team as fix was submitted.
Update released for: python-django Products: SUSE-CLOUD 3.0 (x86_64)
SUSE-SU-2014:0851-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 874950,874955,874956,877993,878641 CVE References: CVE-2014-0472,CVE-2014-0473,CVE-2014-0474,CVE-2014-1418,CVE-2014-3730 Sources used: SUSE Cloud 3 (src): python-django-1.5.8-0.7.1
released
openSUSE-SU-2014:1132-1: An update that fixes 9 vulnerabilities is now available. Category: security (moderate) Bug References: 874950,874955,874956,877993,878641,893087,893088,893089,893090 CVE References: CVE-2014-0472,CVE-2014-0473,CVE-2014-0474,CVE-2014-0480,CVE-2014-0481,CVE-2014-0482,CVE-2014-0483,CVE-2014-1418,CVE-2014-3730 Sources used: openSUSE 13.1 (src): python-django-1.5.10-0.2.8.1 openSUSE 12.3 (src): python-django-1.4.15-2.12.1