VDB
CVE-2008-3909
CVE-2008-3909
PUBLISHED
CVSS 5.800000190734863 MEDIUM
The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.
EPSS 0.93% · 57.3th percentile
Risk Scores
CVSS 2.0
5.800000190734863
EPSS Score
0.93%
57.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| django_project | django | 0.96, 0.91, 0.95 |
| PyPI | Django | 0.91.0, 0.96.0, 0.95.0 |
| n/a | n/a | n/a |
Timeline
- Sep 4, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- 31837 third-party-advisory
- ADV-2008-2533 vdb
- 31961 third-party-advisory
- [oss-security] 20080903 django CSRF vuln mailing-list
- http://www.djangoproject.com/weblog/2008/sep/02/security/ url
- DSA-1640 vendor-advisory
- FEDORA-2008-7288 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=460966 url
- FEDORA-2008-7672 vendor-advisory
- 47906 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-3909 advisory
- https://github.com/django/django/commit/44debfeaa4473bd28872c735dd3d9afde6886752 url
- https://github.com/django/django/commit/7e0972bded362bc4b851c109df2c8a6548481a8e url
- https://github.com/django/django/commit/aee48854a164382c655acb9f18b3c06c3d238e81 url
- https://github.com/django/django package
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2008-2.yaml url
- http://www.djangoproject.com/weblog/2008/sep/02/security url