django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-py-djangoalpine-linux-upgrade-py3-django | Aug 22, 2024 | Feb 5, 2018 | |
| Debian | debian-upgrade-python-django | Jul 30, 2024 | Feb 5, 2018 | |
| Freebsd | freebsd-upgrade-package-py27-django111freebsd-upgrade-package-py34-django111freebsd-upgrade-package-py35-django111freebsd-upgrade-package-py36-django111freebsd-upgrade-package-py27-django20freebsd-upgrade-package-py34-django20freebsd-upgrade-package-py35-django20freebsd-upgrade-package-py36-django20 | Dec 10, 2025 | Feb 2, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-library-python-django-1-11-16-11-4-4-0-1-1-0oracle-solaris-11-4-upgrade-library-python-django-27-1-11-16-11-4-4-0-1-1-0 | Dec 17, 2018 | Feb 4, 2018 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Feb 5, 2018 | |
| Suse | — | suse-upgrade-python-django | Feb 4, 2022 | Feb 4, 2018 |
| Ubuntu | ubuntu-upgrade-python-djangoubuntu-upgrade-python3-django | Feb 8, 2018 | Feb 4, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub