CVE

Id
95834  
CVE No.
CVE-2016-9014  
Status
Candidate  
Description
Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.  
Phase
Assigned (20161025)  
Votes
None (candidate not yet proposed)  
Comments