{"schema_version":"1.7.5","id":"PYSEC-2015-19","published":"2015-06-02T14:59:00Z","modified":"2026-06-10T17:00:58.434252669Z","aliases":["CVE-2015-3982","GHSA-6wgp-fwfm-mxp3"],"details":"The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.","affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.8"},{"fixed":"1.8.2"}]}],"versions":["1.8","1.8.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2015-19.yaml"}}],"references":[{"type":"ARTICLE","url":"https://www.djangoproject.com/weblog/2015/may/20/security-release/"},{"type":"WEB","url":"http://www.securityfocus.com/bid/74960"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6wgp-fwfm-mxp3"}]}