{"id":"CVE-2015-3982","aliases":["PYSEC-2015-19"],"url":"https://o3.security/vulnerability/CVE-2015-3982","summary":"Django allows user sessions hijacking via an empty string in the session key","details":"The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.","published":"2022-05-17T03:29:56Z","modified":"2024-09-17T15:22:38.801640Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"django","fixedVersion":"1.8.2"}],"fix":{"url":"https://github.com/django/django/commit/31cb25adecba930bdeee4556709f5a1c42d88fd6","label":"django/django@31cb25a"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3982"},{"type":"WEB","url":"https://github.com/django/django/commit/31cb25adecba930bdeee4556709f5a1c42d88fd6"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2015-19.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20200228092138/http://www.securityfocus.com/bid/74960"},{"type":"WEB","url":"https://www.djangoproject.com/weblog/2015/may/20/security-release"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-09-17T15:22:38.801640Z"}}