{"id":"GHSA-mwv2-398h-v489","summary":"Django Improper Access Control","details":"The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.","aliases":["CVE-2007-0405","PYSEC-2026-629"],"modified":"2026-07-06T08:11:20.992874900Z","published":"2022-05-01T17:44:04Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-14T17:18:53Z","nvd_published_at":"2007-01-23T00:28:00Z","cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0405"},{"type":"WEB","url":"https://github.com/django/django/commit/3c5782287e"},{"type":"WEB","url":"https://github.com/django/django/commit/e89f0a65581f82a5740bfe989136cea75d09cd67"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31628"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"http://code.djangoproject.com/changeset/3754"}],"affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.95"},{"fixed":"1.0"}]}],"versions":["0.95"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mwv2-398h-v489/GHSA-mwv2-398h-v489.json"}}],"schema_version":"1.9.0"}