Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6188

Опубликовано: 05 фев. 2018
Источник: debian
EPSS Низкий

Описание

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed1:1.11.10-1package
python-djangonot-affectedstretchpackage
python-djangonot-affectedjessiepackage
python-djangonot-affectedwheezypackage

Примечания

  • https://www.djangoproject.com/weblog/2018/feb/01/security-releases/

EPSS

Процентиль: 81%
0.01547
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

CVSS3: 5.3
redhat
больше 7 лет назад

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

CVSS3: 7.5
nvd
больше 7 лет назад

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

CVSS3: 7.5
github
больше 6 лет назад

Django vulnerable to information leakage in AuthenticationForm

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость метода confirm_login_allowed() программной платформы для веб-приложений Django, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 81%
0.01547
Низкий