Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-6188

Опубликовано: 05 фев. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

Отчет

This issue affects the versions of python-django as shipped with Red Hat Satellite version 6. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. This issue affects the versions of python-django as shipped with Red Hat Subscription Asset Manager version 1. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3DjangoNot affected
Red Hat Ceph Storage 2python-djangoNot affected
Red Hat Ceph Storage 3python-djangoNot affected
Red Hat Enterprise Linux 8python-djangoWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Toolspython-djangoNot affected
Red Hat OpenStack Platform 10 (Newton)python-djangoNot affected
Red Hat OpenStack Platform 11 (Ocata)python-djangoNot affected
Red Hat OpenStack Platform 12 (Pike)python-djangoNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1538793django: Information leakage in AuthenticationForm

EPSS

Процентиль: 72%
0.0074
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

CVSS3: 7.5
nvd
больше 7 лет назад

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

CVSS3: 7.5
debian
больше 7 лет назад

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0. ...

CVSS3: 7.5
github
почти 7 лет назад

Django vulnerable to information leakage in AuthenticationForm

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость метода confirm_login_allowed() программной платформы для веб-приложений Django, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 72%
0.0074
Низкий

5.3 Medium

CVSS3