Listen to this Post
The vulnerability exists in Django’s CORS middleware. When processing a request, if the `Origin` header was present and the allowed hosts list was not set to a wildcard (""), the middleware would incorrectly copy the incoming request’s `Vary` header and reflect it into the response. The `Vary` header is a critical HTTP response header that dictates how caching systems (like CDNs or proxies) generate their cache keys. By allowing an attacker to control this value via a crafted request, the cache key could be polluted. For example, an attacker could set the request’s `Vary` header to Accept-Encoding, User-Agent, Origin. This manipulated value would then be reflected in the response, instructing caches to create separate entries based on all those headers. This could lead to cache poisoning where a cached response intended for one user is incorrectly served to another, or it could cause inefficient cache usage and inconsistent CORS policy application due to a fragmented cache.
Platform: Django
Version: < patched
Vulnerability: Cache Poisoning
Severity: Low
date: 2023-10-XX
Prediction: 2023-10-26
What Undercode Say:
Checking for vulnerable CORS configuration grep -r "CORS_ORIGIN_ALLOW_ALL" myproject/ grep -r "CORS_ALLOWED_ORIGINS" myproject/ Example of a malicious request with a controlled Vary header curl -H "Origin: http://malicious.com" -H "Vary: User-Agent, Accept-Encoding, X-Injected-Header" http://vulnerable-django-app.com/api/data
Example of a patched CORS middleware logic (simplified)
The vulnerable code copied the request's Vary header.
old_vulnerable_code.py
response[bash] = request.META.get('HTTP_VARY', '')
The patched code manages the Vary header exclusively.
corrected_code.py
if request.META.get('HTTP_ORIGIN'):
if origin not in self.allowed_origins and not self.origin_wildcard:
response[bash] = 'Origin' Server-controlled value only
How Exploit:
Attacker sends requests with manipulated Vary headers to poison cache keys, leading to inconsistent CORS application and cache fragmentation.
Protection from this CVE
Update Django to the patched version that no longer reflects the request’s Vary header. Ensure the CORS_ORIGIN_ALLOW_ALL setting is False for production if using wildcards. Configure CDNs and reverse proxies to ignore client-supplied Vary headers.
Impact:
Cache key pollution, potential for inconsistent CORS enforcement, and reduced cache efficiency. No direct data breach or system compromise in default setups.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

