Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wph-fc4w-wqp2

Опубликовано: 23 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 6.6
CVSS3: 7.5

Описание

Improper date handling in Django

The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.1.3

1.1.3

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.2, < 1.2.4

1.2.4

EPSS

Процентиль: 89%
0.04746
Низкий

6.6 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 14 лет назад

The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.

nvd
больше 14 лет назад

The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.

debian
больше 14 лет назад

The password reset functionality in django.contrib.auth in Django befo ...

EPSS

Процентиль: 89%
0.04746
Низкий

6.6 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20