The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key. <a href"http://cwe.mitre.org/data/definitions/384.html">CWE-384: Session Fixation</a>
Publication date: Tue, 02 Jun 2015 19:59:00 +0000