User Enumeration Vulnerability in Django Authentication System by Django Software Foundation
CVE-2024-45231
5.3MEDIUM
What is CVE-2024-45231?
A security issue has been identified in specific versions of Django that facilitates user enumeration through the password reset process. Attackers can exploit this vulnerability by sending multiple password reset requests to determine valid user email addresses based on the response outcomes, specifically when email sending fails consistently. This could lead to unauthorized access and information disclosure, making it imperative for organizations using affected versions to implement necessary updates and security measures.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved