PublicDateAtUSN: 2016-09-26 18:00:00 Candidate: CVE-2016-7401 CRD: 2016-09-26 18:00:00 PublicDate: 2016-10-03 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7401 https://www.djangoproject.com/weblog/2016/sep/26/security-releases/ https://ubuntu.com/security/notices/USN-3089-1 Description: The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Sergey Bobrov Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_python-django: upstream_python-django: released (1.8.15,1.9.10) precise_python-django: released (1.3.1-4ubuntu1.21) trusty_python-django: released (1.6.1-2ubuntu0.15) trusty/esm_python-django: released (1.6.1-2ubuntu0.15) vivid/stable-phone-overlay_python-django: DNE vivid/ubuntu-core_python-django: DNE xenial_python-django: released (1.8.7-1ubuntu5.2) esm-infra/xenial_python-django: released (1.8.7-1ubuntu5.2) devel_python-django: released (1.8.7-1ubuntu8)