Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-32879

Опубликовано: 24 апр. 2024
Источник: redhat
CVSS3: 4.9

Описание

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.

A flaw was found in social-auth-app-django. In affected versions of this package, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2ansible-towerOut of support scope
Red Hat Satellite 6python-social-auth-app-djangoAffected
Red Hat Ansible Automation Platform 2.4 for RHEL 8python3x-social-auth-app-djangoFixedRHSA-2024:378110.06.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 8automation-controllerFixedRHSA-2024:642805.09.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 9python-social-auth-app-djangoFixedRHSA-2024:378110.06.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 9automation-controllerFixedRHSA-2024:642805.09.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-178
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2277035python-social-auth: Improper Handling of Case Sensitivity in social-auth-app-django

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 2 года назад

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.

CVSS3: 4.9
nvd
почти 2 года назад

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.

CVSS3: 4.9
debian
почти 2 года назад

Python Social Auth is a social authentication/registration mechanism. ...

CVSS3: 4.9
github
почти 2 года назад

social-auth-app-django affected by Improper Handling of Case Sensitivity

4.9 Medium

CVSS3