QID 980887
QID 980887: Python (pip) Security Update for django (GHSA-rf4j-j272-fj86)
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rf4j-j272-fj86 for updates pertaining to this vulnerability.
Vendor References
- GHSA-rf4j-j272-fj86 -
github.com/advisories/GHSA-rf4j-j272-fj86
CVEs related to QID 980887
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rf4j-j272-fj86 | django |
|