Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.13"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.14"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15"
},
{
"introduced": "0"
},
{
"last_affected": "1.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.10"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.10"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9014.json"