Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poisoning attacks via a crafted request.
{ "nvd_published_at": "2011-10-19T10:55:00Z", "cwe_ids": [ "CWE-20", "CWE-349" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-16T22:47:59Z" }