Описание
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1.5.4 |
lucid | released | 1.1.1-2ubuntu1.9 |
precise | released | 1.3.1-4ubuntu1.8 |
quantal | released | 1.4.1-2ubuntu0.4 |
raring | released | 1.4.5-1ubuntu0.1 |
upstream | released | 1.5.4 |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.
The authentication framework (django.contrib.auth) in Django 1.4.x bef ...
Django Denial of Service Vulnerability in the authentication framework
EPSS
5 Medium
CVSS2