User Enumeration Vulnerability in Django Authentication System by Django Software Foundation
CVE-2024-45231

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 October 2024

What is CVE-2024-45231?

A security issue has been identified in specific versions of Django that facilitates user enumeration through the password reset process. Attackers can exploit this vulnerability by sending multiple password reset requests to determine valid user email addresses based on the response outcomes, specifically when email sending fails consistently. This could lead to unauthorized access and information disclosure, making it imperative for organizations using affected versions to implement necessary updates and security measures.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.