CVE-2016-7401 - log back

CVE-2016-7401 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Remote
Type
+ Cross-site request forgery
Description
+ Sergey Bobrov found a vulnerability where an interaction between Google Analytics and Django's cookie parsing could allow an attacker to set arbitrary cookies leading to a bypass of CSRF protection.
References
+ https://www.djangoproject.com/weblog/2016/sep/26/security-releases/
Notes