django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.
2018-02-05T03:29:00.267
2024-11-21T04:10:15.193
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | djangoproject | django | 1.11.8 | Yes |
Application | djangoproject | django | 1.11.9 | Yes |
Application | djangoproject | django | 2.0 | Yes |
Application | djangoproject | django | 2.0.1 | Yes |
Operating System | canonical | ubuntu_linux | 17.10 | Yes |