Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-32879

Опубликовано: 24 апр. 2024
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.

A flaw was found in social-auth-app-django. In affected versions of this package, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2ansible-towerOut of support scope
Red Hat Satellite 6python-social-auth-app-djangoAffected
Red Hat Ansible Automation Platform 2.4 for RHEL 8python3x-social-auth-app-djangoFixedRHSA-2024:378110.06.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 8automation-controllerFixedRHSA-2024:642805.09.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 9python-social-auth-app-djangoFixedRHSA-2024:378110.06.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 9automation-controllerFixedRHSA-2024:642805.09.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-178
https://bugzilla.redhat.com/show_bug.cgi?id=2277035python-social-auth: Improper Handling of Case Sensitivity in social-auth-app-django

EPSS

Процентиль: 46%
0.00581
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 2 лет назад

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.

CVSS3: 4.9
nvd
больше 2 лет назад

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.

CVSS3: 4.9
debian
больше 2 лет назад

Python Social Auth is a social authentication/registration mechanism. ...

CVSS3: 4.9
github
больше 2 лет назад

social-auth-app-django affected by Improper Handling of Case Sensitivity

EPSS

Процентиль: 46%
0.00581
Низкий

4.9 Medium

CVSS3