CVE-2014-0482
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0071 (0.7%)
Percentile: 72.3%
EPSS: 2026-05-06
Affects
opensuse:opensusedjangoproject:djangoTechnical description
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.
Published: 8/26/2014, 2:55:05 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.html
- http://secunia.com/advisories/59782
- http://secunia.com/advisories/61276
- http://secunia.com/advisories/61281
- http://www.debian.org/security/2014/dsa-3010
- https://www.djangoproject.com/weblog/2014/aug/20/security/
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.html
- http://secunia.com/advisories/59782