Junglewise Threat Intelligence

CVE-2011-0696: Django CSRF protection bypass via X-Requested-With header

CVE-2011-0696 · Severity: high · CVSS 7.5 · Published 2018-07-23

Technologies: Django (PyPI), Django. Vendors: PyPI, Django.

Executive brief

Django, a popular web framework for Python, was found to have a security flaw in how it handles certain web requests. This vulnerability could allow an attacker to trick a user's browser into performing unauthorized actions on a website where they are logged in. This could lead to unauthorized data modifications or account changes without the user's knowledge.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Django versions 1.1.x (before 1.1.4) and 1.2.x (before 1.2.5). The framework failed to properly validate HTTP requests containing the 'X-Requested-With' header, which was previously relied upon to identify AJAX requests that were thought to be immune to CSRF. Attackers can bypass this protection using a combination of browser plugins and redirects to forge AJAX requests. This allows a remote attacker to perform state-changing actions on behalf of an authenticated user. The issue is resolved in Django versions 1.1.4 and 1.2.5.

Affected products

  • Django Django >= 1.1, < 1.1.4; >= 1.2, < 1.2.5

Timeline

  • 2011-02-08: advisory: Django security release announcement
  • 2011-02-14: disclosed: NVD publication date
  • 2018-07-23: other: GitHub Advisory Database publication date

References

Related threats