#15845 closed Bug (invalid)

CSRF validation leak

Description (last modified by Russell Keith-Magee)

The CSRF validation compares request.COOKIES[settings.CSRF_COOKIE_NAME] and request.POST.get('csrfmiddlewaretoken', ) to see if a request is legal. But unfortunately both two values are provided by the client side, and they are the same. So it is easy for attackers to fake a request that no 403 will be thrown.

The attached project provides one url entry that returns "ok", unless CSRF fails. Following cmds show how to cheat.

# 200

# 200
curl -G -d test=test

# 403
curl -d test=test

# 200
curl -d "test=test;csrfmiddlewaretoken=1" -b csrftoken=1

comment:1 Changed 6 years ago by Luke Plant

Resolution: invalid
Status: newclosed

This does not result in a CSRF vulnerability. curl is irrelevant - CSRF is about browsers being abused.

comment:2 Changed 6 years ago by Russell Keith-Magee

I would also point out that if you even *suspect* that you have found a security issue with Django, *DO NOT* report it in Trac. Mail security@… instead.

