CVE-2016-9014
high
CVSS v3
8.1
CVSS v2
6.8
VIR risk
8.1
Description
Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.
Predictions
Exploit likelihood
88%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-9014
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-9014.html
Vendor advisory: cve@mitre.org — https://www.djangoproject.com/weblog/2016/nov/01/security-releases/
Vendor advisory: arch — https://security.archlinux.org/ASA-201611-15
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| arch | fixed | 1.10.3-1 | |
| ubuntu | 12.04 | affected | |
| ubuntu | 14.04 | affected | |
| ubuntu | 16.04 | affected | |
| ubuntu | 16.10 | affected | |
| fedora | 24 | affected | |
| fedora | 25 | affected | |
| debian | bookworm | fixed | 1:1.10.3-1 |
| debian | bullseye | fixed | 1:1.10.3-1 |
| debian | forky | fixed | 1:1.10.3-1 |
| debian | sid | fixed | 1:1.10.3-1 |
| debian | trixie | fixed | 1:1.10.3-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| djangoproject | django | 1.8 | |
| djangoproject | django | 1.8.1 | |
| djangoproject | django | 1.8.2 | |
| djangoproject | django | 1.8.3 | |
| djangoproject | django | 1.8.4 | |
| djangoproject | django | 1.8.5 | |
| djangoproject | django | 1.8.6 | |
| djangoproject | django | 1.8.7 | |
| djangoproject | django | 1.8.8 | |
| djangoproject | django | 1.8.9 | |
| djangoproject | django | 1.8.10 | |
| djangoproject | django | 1.8.11 | |
| djangoproject | django | 1.8.12 | |
| djangoproject | django | 1.8.13 | |
| djangoproject | django | 1.8.14 | |
| djangoproject | django | 1.8.15 | |
| djangoproject | django | 1.10 | |
| djangoproject | django | 1.10.1 | |
| djangoproject | django | 1.10.2 | |
| djangoproject | django | 1.9 | |
| djangoproject | django | 1.9.1 | |
| djangoproject | django | 1.9.2 | |
| djangoproject | django | 1.9.3 | |
| djangoproject | django | 1.9.4 | |
| djangoproject | django | 1.9.5 | |
| djangoproject | django | 1.9.6 | |
| djangoproject | django | 1.9.7 | |
| djangoproject | django | 1.9.8 | |
| djangoproject | django | 1.9.9 | |
| djangoproject | django | 1.9.10 | |
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-9014
- https://github.com/django/django/commit/45acd6d836895a4c36575f48b3fb36a3dae98d19
- https://github.com/django/django/commit/884e113838e5a72b4b0ec9e5e87aa480f6aa4472
- https://github.com/django/django/commit/c401ae9a7dfb1a94a8a61927ed541d6f93089587
- https://github.com/django/django
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2016-18.yaml
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OG5ROMUPS6C7BXELD3TAUUH7OBYV56WQ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXDKJYHN74BWY3P7AR2UZDVJREQMRE6S
- https://web.archive.org/web/20210123185619/http://www.securityfocus.com/bid/94068
- https://web.archive.org/web/20211204043252/http://www.securitytracker.com/id/1037159
- https://www.djangoproject.com/weblog/2016/nov/01/security-releases
- http://www.debian.org/security/2017/dsa-3835
- http://www.ubuntu.com/usn/USN-3115-1
- https://security.archlinux.org/ASA-201611-15
- http://www.securityfocus.com/bid/94068
- http://www.securitytracker.com/id/1037159
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OG5ROMUPS6C7BXELD3TAUUH7OBYV56WQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QXDKJYHN74BWY3P7AR2UZDVJREQMRE6S/
- https://www.djangoproject.com/weblog/2016/nov/01/security-releases/
- https://www.suse.com/security/cve/CVE-2016-9014.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXDKJYHN74BWY3P7AR2UZDVJREQMRE6S/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OG5ROMUPS6C7BXELD3TAUUH7OBYV56WQ/
- https://security-tracker.debian.org/tracker/CVE-2016-9014
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.