CVE-2015-5963Allocation of Resources Without Limits or Throttling in Django

Severity
5.0MEDIUMNVD
EPSS
5.2%
top 10.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateMay 17

Description

contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consumption or session record removal) via a large number of requests to contrib.auth.views.logout, which triggers the creation of an empty session record.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

PyPIdjangoproject/django1.81.8.4+2
NVDdjangoproject/django33 versions+32
NVDoracle/solaris11.3

Also affects: Ubuntu Linux 12.04, 14.04, 15.04

Patches

🔴Vulnerability Details

4
GHSA
Django denial of service via empty session record creation2022-05-17
OSV
Django denial of service via empty session record creation2022-05-17
CVEList
CVE-2015-5963: contrib2015-08-24
OSV
CVE-2015-5963: contrib2015-08-24

📋Vendor Advisories

3
Red Hat
python-django: Denial-of-service possibility in logout() view by filling session store2015-08-18
Ubuntu
Django vulnerability2015-08-18
Debian
CVE-2015-5963: python-django - contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7....2015

💬Community

3
Bugzilla
CVE-2015-5963 python-django: Denial-of-service possibility in logout() view by filling session store [fedora-all]2015-08-19
Bugzilla
CVE-2015-5963 python-django: Denial-of-service possibility in logout() view by filling session store2015-08-12
Bugzilla
CVE-2015-5964 python-django: Denial-of-service possibility in logout() view by filling session store2015-08-12
CVE-2015-5963 — Djangoproject Django vulnerability | cvebase