VYPR
Moderate severityNVD Advisory· Published Aug 24, 2015· Updated Jun 17, 2026

CVE-2015-5963

CVE-2015-5963

Description

contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consumption or session record removal) via a large number of requests to contrib.auth.views.logout, which triggers the creation of an empty session record.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
DjangoPyPI
>= 1.8, < 1.8.41.8.4
DjangoPyPI
>= 1.7, < 1.7.101.7.10
DjangoPyPI
>= 1.4, < 1.4.221.4.22

Affected products

51
  • cpe:2.3:a:djangoproject:django:1.4:*:*:*:*:*:*:*+ 38 more
    • cpe:2.3:a:djangoproject:django:1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.10:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.12:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.13:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.14:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.17:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.19:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.20:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.21:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.4:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.8:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.4.9:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.4:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.5:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.6:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.7:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.8:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7.9:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7:beta1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7:beta2:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7:beta3:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7:beta4:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7:rc1:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7:rc2:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.7:rc3:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:djangoproject:django:1.8:beta1:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
  • cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

24

News mentions

0

No linked articles in our index yet.