Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mcm-79hx-8fxw

Опубликовано: 03 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.7

Описание

Django has Observable Timing Discrepancy

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.

The django.contrib.auth.handlers.modwsgi.check_password() function for authentication via mod_wsgi allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.

Django would like to thank Stackered for reporting this issue.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 6.0a1, < 6.0.2

6.0.2

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.2a1, < 5.2.11

5.2.11

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2a1, < 4.2.28

4.2.28

EPSS

Процентиль: 50%
0.00713
Низкий

2.7 Low

CVSS4

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

CVSS3: 5.3
redhat
6 месяцев назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

CVSS3: 5.3
nvd
6 месяцев назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

CVSS3: 5.3
debian
6 месяцев назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4. ...

CVSS3: 5.3
fstec
6 месяцев назад

Уязвимость программной платформы для веб-приложений Django, связанная с раскрытием информации на основании временных расхождений, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 50%
0.00713
Низкий

2.7 Low

CVSS4

Дефекты

CWE-208