QID 981220
QID 981220: Python (pip) Security Update for django (GHSA-7wph-fc4w-wqp2)
The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7wph-fc4w-wqp2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-7wph-fc4w-wqp2 -
github.com/advisories/GHSA-7wph-fc4w-wqp2
CVEs related to QID 981220
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7wph-fc4w-wqp2 | django |
|