Description
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2024-30100 Vulnerability (CVE-2024-30100)
WordPress Plugin External Media Arbitrary File Upload (1.0.33)
MongoDb Improper Input Validation Vulnerability (CVE-2021-20330)
MySQL CVE-2014-6478 Vulnerability (CVE-2014-6478)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2021-41524)