#31412: database timing attack against sessions
--------------------------------------------+------------------------
               Reporter:  Brian May         |          Owner:  nobody
                   Type:  Bug               |         Status:  new
              Component:  contrib.sessions  |        Version:  3.0
               Severity:  Normal            |       Keywords:
           Triage Stage:  Unreviewed        |      Has patch:  0
    Needs documentation:  0                 |    Needs tests:  0
Patch needs improvement:  0                 |  Easy pickings:  0
                  UI/UX:  0                 |
--------------------------------------------+------------------------
 CVE-2019-16782 was assigned to Ruby Rack. Basically, an attacker, can
 conduct a timing attack by sending specially crafted session ids and
 timing how long it takes for the database to lookup the session. From this
 the attacker can guess valid session ids.

 To me it looks like Django, by default, stores sessions on the database
 (using django.contrib.sessions.backends.db) in a very similar manner. Does
 this also mean it is vulnerable to the same timing attack?

-- 
Ticket URL: <https://code.djangoproject.com/ticket/31412>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/048.2659978d1f78b6f245646dfc624b3144%40djangoproject.com.

Reply via email to