|
|
| |
|
| |
python-django: information disclosure
| Package(s): | python-django |
CVE #(s): | CVE-2012-4520
|
| Created: | October 30, 2012 |
Updated: | March 8, 2013 |
| Description: |
From the Mageia advisory:
The Host header parsing in Django 1.3 and Django 1.4 -- specifically,
django.http.HttpRequest.get_host() -- was incorrectly handling
username/password information in the header.
Using this, an attacker can cause parts of Django -- particularly the
password-reset mechanism -- to generate and display arbitrary URLs to
users. |
| Alerts: |
|
( Log in to post comments)
|
|
|