CVE-2016-7401
python-django: CSRF protection bypass on a site with Google Analytics
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.
El código de análisis de cookie en Django en versiones anteriores a 1.8.15 y 1.9.x en versiones anteriores a 1.9.10, cuando se utiliza en un sitio con Google Analytics, permite a atacantes remotos eludir un mecanismo de protección CSRF destinado estableciendo cookies arbitrarias.
A CSRF flaw was found in Django, where an interaction between Google Analytics and Django's cookie parsing could allow an attacker to set arbitrary cookies leading to a bypass of CSRF protection. In this update, the parser for ''request.COOKIES'' has been simplified to better match browser behavior and to mitigate this attack. ''request.COOKIES'' may now contain cookies that are invalid according to RFC 6265 but are possible to set using ''document.cookie''.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-09-09 CVE Reserved
- 2016-09-27 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-254: 7PK - Security Features
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/93182 | Third Party Advisory | |
http://www.securitytracker.com/id/1036899 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.djangoproject.com/weblog/2016/sep/26/security-releases | 2018-01-05 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2016-2038.html | 2018-01-05 | |
http://rhn.redhat.com/errata/RHSA-2016-2039.html | 2018-01-05 | |
http://rhn.redhat.com/errata/RHSA-2016-2040.html | 2018-01-05 | |
http://rhn.redhat.com/errata/RHSA-2016-2041.html | 2018-01-05 | |
http://rhn.redhat.com/errata/RHSA-2016-2042.html | 2018-01-05 | |
http://rhn.redhat.com/errata/RHSA-2016-2043.html | 2018-01-05 | |
http://www.debian.org/security/2016/dsa-3678 | 2018-01-05 | |
http://www.ubuntu.com/usn/USN-3089-1 | 2018-01-05 | |
https://access.redhat.com/security/cve/CVE-2016-7401 | 2016-10-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1377376 | 2016-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 14.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | <= 1.8.14 Search vendor "Djangoproject" for product "Django" and version " <= 1.8.14" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.0 Search vendor "Djangoproject" for product "Django" and version "1.9.0" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.1 Search vendor "Djangoproject" for product "Django" and version "1.9.1" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.2 Search vendor "Djangoproject" for product "Django" and version "1.9.2" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.3 Search vendor "Djangoproject" for product "Django" and version "1.9.3" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.4 Search vendor "Djangoproject" for product "Django" and version "1.9.4" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.5 Search vendor "Djangoproject" for product "Django" and version "1.9.5" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.6 Search vendor "Djangoproject" for product "Django" and version "1.9.6" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.7 Search vendor "Djangoproject" for product "Django" and version "1.9.7" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.8 Search vendor "Djangoproject" for product "Django" and version "1.9.8" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | 1.9.9 Search vendor "Djangoproject" for product "Django" and version "1.9.9" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|