VDB

CVE-2016-7401

CVE-2016-7401 PUBLISHED

The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.

EPSS 6.16% · 91.0th percentile

Risk Scores

EPSS Score
6.16%
91.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSpython-django1.5.4-1ubuntu1, 1.6-1, 1.6.1-1
Ubuntu:16.04:LTSpython-django0, 1.7.9-1ubuntu5, 1.8.5-2ubuntu1

Timeline

  • Sep 26, 2016 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Dec 17, 2024 EPSS Score
  • Mar 25, 2025 EPSS Score
  • Mar 26, 2025 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Mar 30, 2025 EPSS Score
  • Apr 2, 2025 EPSS Score
  • Apr 3, 2025 EPSS Score
  • Apr 7, 2025 EPSS Score
  • Apr 8, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›