The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/31628 | vdb entry |
http://secunia.com/advisories/23826 | third party advisory patch vendor advisory |
http://code.djangoproject.com/changeset/3754 | |
http://www.securityfocus.com/bid/22138 | vdb entry |