Логотип exploitDog
bind:CVE-2025-13473
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-13473

Количество 4

Количество 4

ubuntu логотип

CVE-2025-13473

6 дней назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-13473

6 дней назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-13473

6 дней назад

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4. ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mcm-79hx-8fxw

6 дней назад

Django has Observable Timing Discrepancy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-13473

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

CVSS3: 5.3
0%
Низкий
6 дней назад
nvd логотип
CVE-2025-13473

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

CVSS3: 5.3
0%
Низкий
6 дней назад
debian логотип
CVE-2025-13473

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4. ...

CVSS3: 5.3
0%
Низкий
6 дней назад
github логотип
GHSA-2mcm-79hx-8fxw

Django has Observable Timing Discrepancy

0%
Низкий
6 дней назад

Уязвимостей на страницу