The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.6.1-2ubuntu0.9", "binary_name": "python-django" }, { "binary_version": "1.6.1-2ubuntu0.9", "binary_name": "python-django-doc" } ] }