[Django] #32562: Broken Authentication (Insecure CSRF and Session ID)

8 views
Skip to first unread message

Django

unread,
Mar 17, 2021, 9:48:40 AM3/17/21
to django-...@googlegroups.com
#32562: Broken Authentication (Insecure CSRF and Session ID)
---------------------------------------------+------------------------
Reporter: cpulidomagentrack | Owner: nobody
Type: Bug | Status: new
Component: CSRF | Version: 3.1
Severity: Normal | Keywords:
Triage Stage: Unreviewed | Has patch: 0
Needs documentation: 0 | Needs tests: 0
Patch needs improvement: 0 | Easy pickings: 0
UI/UX: 0 |
---------------------------------------------+------------------------
We have currently carried out security tests on our system developed with
Django, our security specialists report a vulnerability to us when a CSRF
(Broken Authentication) token is obtained.
(Insecure CSRF and Session ID)), since if this token is obtained it is
possible to reuse it several times allowing brute force attacks. Is it
possible to modify the validity of this token or disable it when it is
consumed in a post/put request and generate a new token within the session
or limited the time valid from the inicial token CSRF ?

--
Ticket URL: <https://code.djangoproject.com/ticket/32562>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

Django

unread,
Mar 17, 2021, 10:59:38 AM3/17/21
to django-...@googlegroups.com
#32562: Broken Authentication (Insecure CSRF and Session ID)
-----------------------------------+--------------------------------------
Reporter: cpulidomagentrack | Owner: nobody
Type: Bug | Status: closed
Component: CSRF | Version: 3.1
Severity: Normal | Resolution: needsinfo

Keywords: | Triage Stage: Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-----------------------------------+--------------------------------------
Changes (by Carlton Gibson):

* status: new => closed
* resolution: => needsinfo


Comment:

There's not sufficient detail here to assess. As well it's a security
report and should not be made in public.

Please follow up with sufficient detail to reproduce to
secu...@djangoproject.com

This is highlighted before creating an issue:

> If your bug report is a security issue, DO NOT report it with a ticket.
Please read our
[https://docs.djangoproject.com/en/dev/internals/contributing/bugs-and-
features/#reporting-security-issues ​guide to reporting security issues].

--
Ticket URL: <https://code.djangoproject.com/ticket/32562#comment:1>

Django

unread,
Mar 17, 2021, 3:59:02 PM3/17/21
to django-...@googlegroups.com
#32562: Broken Authentication (Insecure CSRF and Session ID)
-----------------------------------+--------------------------------------
Reporter: cpulidomagentrack | Owner: nobody
Type: Bug | Status: closed
Component: CSRF | Version: 3.1
Severity: Normal | Resolution: invalid

Keywords: | Triage Stage: Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-----------------------------------+--------------------------------------
Changes (by Mariusz Felisiak):

* resolution: needsinfo => invalid


--
Ticket URL: <https://code.djangoproject.com/ticket/32562#comment:2>

Reply all
Reply to author
Forward
0 new messages