Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfq6-hq5r-27r6

Опубликовано: 16 янв. 2020
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Django Potential account hijack via password reset form

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.11.27

1.11.27

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 2.0, < 2.2.9

2.2.9

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 3.0, < 3.0.1

3.0.1

EPSS

Процентиль: 94%
0.12612
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

CVSS3: 9.8
redhat
больше 5 лет назад

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

CVSS3: 9.8
nvd
больше 5 лет назад

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

CVSS3: 9.8
debian
больше 5 лет назад

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows a ...

CVSS3: 7.5
fstec
больше 5 лет назад

Уязвимость фреймворка для веб-приложений Django, связанная с ошибкой в работе механизма восстановления паролей, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 94%
0.12612
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-640