GHSA-rf4j-j272-fj86

Suggest an improvement
Source
https://github.com/advisories/GHSA-rf4j-j272-fj86
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-rf4j-j272-fj86/GHSA-rf4j-j272-fj86.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rf4j-j272-fj86
Aliases
Published
2018-10-03T21:13:54Z
Modified
2024-09-18T20:08:51.348160Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Django vulnerable to information leakage in AuthenticationForm
Details

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:54:30Z"
}
References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0a1
Fixed
2.0.2

Affected versions

2.*

2.0a1
2.0b1
2.0rc1
2.0
2.0.1

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.11.8
Fixed
1.11.10

Affected versions

1.*

1.11.8
1.11.9