Lack of data validation - Path Traversal In python-django
Description
Django has Observable Timing Discrepancy An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
The django.contrib.auth.handlers.modwsgi.check_password() function for authentication via mod_wsgi allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Stackered for reporting this issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 2:2.2.28-1~deb11u12 | ||
pypi | 6.0.2, 5.2.11, 4.2.28 | ||
debian 13 | 3:4.2.28-0+deb13u1 | ||
debian 12 | 3:3.2.25-0+deb12u2 | ||
debian 14 | 3:4.2.28-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.