{"id":"CVE-2007-0405","aliases":["GHSA-mwv2-398h-v489","PYSEC-2026-629"],"url":"https://o3.security/vulnerability/CVE-2007-0405","summary":"Django Improper Access Control","details":"The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.","published":"2007-01-23T00:28:00Z","modified":"2026-07-06T08:11:20.992874900Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"django","fixedVersion":"1.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/23826"},{"type":"FIX","url":"http://secunia.com/advisories/23826"},{"type":"WEB","url":"http://code.djangoproject.com/changeset/3754"},{"type":"WEB","url":"http://www.securityfocus.com/bid/22138"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31628"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-06T08:11:20.992874900Z"}}