Executive brief
Django, a popular web framework for Python, was found to have a security flaw in how it handles certain web requests. This vulnerability could allow an attacker to trick a user's browser into performing unauthorized actions on a website where they are logged in. This could lead to unauthorized data modifications or account changes without the user's knowledge.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Django versions 1.1.x (before 1.1.4) and 1.2.x (before 1.2.5). The framework failed to properly validate HTTP requests containing the 'X-Requested-With' header, which was previously relied upon to identify AJAX requests that were thought to be immune to CSRF. Attackers can bypass this protection using a combination of browser plugins and redirects to forge AJAX requests. This allows a remote attacker to perform state-changing actions on behalf of an authenticated user. The issue is resolved in Django versions 1.1.4 and 1.2.5.
Affected products
- Django Django >= 1.1, < 1.1.4; >= 1.2, < 1.2.5
Timeline
- 2011-02-08: advisory: Django security release announcement
- 2011-02-14: disclosed: NVD publication date
- 2018-07-23: other: GitHub Advisory Database publication date