Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2014-1418

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.

  • Published: May 16, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-1418
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.4
  • AV:N/AC:L/Au:N/C:P/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
djangoproject / django 1.7-beta1 1.7-beta1.x
djangoproject / django 1.7-beta3 1.7-beta3.x
djangoproject / django 1.7-beta2 1.7-beta2.x
djangoproject / django 1.4.12 1.4.12.x
djangoproject / django 1.4.9 1.4.9.x
djangoproject / django 1.4.10 1.4.10.x
djangoproject / django 1.4.6 1.4.6.x
djangoproject / django 1.4.4 1.4.4.x
djangoproject / django 1.4.5 1.4.5.x
djangoproject / django 1.4.2 1.4.2.x
djangoproject / django 1.4.11 1.4.11.x
djangoproject / django 1.4.7 1.4.7.x
djangoproject / django 1.4.8 1.4.8.x
djangoproject / django 1.4 1.4.x
djangoproject / django 1.4.1 1.4.1.x
djangoproject / django 1.5 1.5.x
djangoproject / django 1.5.7 1.5.7.x
djangoproject / django 1.5.1 1.5.1.x
djangoproject / django 1.5.3 1.5.3.x
djangoproject / django 1.5.4 1.5.4.x
djangoproject / django 1.5-beta 1.5-beta.x
djangoproject / django 1.5.5 1.5.5.x
djangoproject / django 1.5.2 1.5.2.x
djangoproject / django 1.5-alpha 1.5-alpha.x
djangoproject / django 1.5.6 1.5.6.x
canonical / ubuntu_linux 13.10 13.10.x
canonical / ubuntu_linux 12.10 12.10.x
canonical / ubuntu_linux 14.04 14.04.x
canonical / ubuntu_linux 12.04 12.04.x
canonical / ubuntu_linux 10.04 10.04.x
djangoproject / django 1.6-beta4 1.6-beta4.x
djangoproject / django 1.6-beta2 1.6-beta2.x
djangoproject / django 1.6.3 1.6.3.x
djangoproject / django 1.6.4 1.6.4.x
djangoproject / django 1.6 1.6.x
djangoproject / django 1.6.1 1.6.1.x
djangoproject / django 1.6.2 1.6.2.x
djangoproject / django 1.6-beta1 1.6-beta1.x
djangoproject / django 1.6-beta3 1.6-beta3.x