CVE Vulnerabilities

CVE-2024-45231

Published: Oct 08, 2024 | Modified: Oct 19, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
LOW

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).

Affected Software

Name Vendor Start Version End Version
Django Djangoproject 4.2.0 (including) 4.2.16 (excluding)
Django Djangoproject 5.0 (including) 5.0.9 (excluding)
Django Djangoproject 5.1 (including) 5.1 (including)
Python-django Ubuntu devel *
Python-django Ubuntu esm-infra/bionic *
Python-django Ubuntu focal *
Python-django Ubuntu jammy *
Python-django Ubuntu noble *
Python-django Ubuntu oracular *

References