Input validation error in Django - CVE-2015-5144
Published: July 14, 2015 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to the (3) validate_ipv4_address or (4) validate_slug validator.
Affected software
Gentoo Linux
Fedora
py-django (Alpine package)
Django14
python-django
How to mitigate CVE-2015-5144
py-django (Alpine package) - update to 1.7.9-r0
Django14 - update to 1.4.21-1.el6
python-django - update to 1.8.3-1.fc22
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172084.html
- http://lists.opensuse.org/opensuse-updates/2015-10/msg00043.html
- http://lists.opensuse.org/opensuse-updates/2015-10/msg00046.html
- http://www.debian.org/security/2015/dsa-3305
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.securityfocus.com/bid/75665
- http://www.securitytracker.com/id/1032820
- http://www.ubuntu.com/usn/USN-2671-1
- https://security.gentoo.org/glsa/201510-06
- https://www.djangoproject.com/weblog/2015/jul/08/security-releases/