Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c42-4rxm-x6qf

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Django Denial of Service Vulnerability in the authentication framework

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.4, < 1.4.8

1.4.8

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.5, < 1.5.4

1.5.4

EPSS

Процентиль: 78%
0.01174
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

ubuntu
больше 11 лет назад

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

redhat
почти 12 лет назад

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

nvd
больше 11 лет назад

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

debian
больше 11 лет назад

The authentication framework (django.contrib.auth) in Django 1.4.x bef ...

EPSS

Процентиль: 78%
0.01174
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400