ZeroHour

CVE-2016-9014

CVSS 3.0
8.1 high
EPSS
6%p93
Published
()
Modified
Description

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

Vendors
fedoraprojectcanonicaldjangoproject
Products
fedora, ubuntu linux, django
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.