CVE-2013-1443: High severity djangoproject Django vulnerability
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1443?
CVE-2013-1443 has a medium severity rating due to its potential to cause denial of service through excessive CPU usage.
How do I fix CVE-2013-1443?
To fix CVE-2013-1443, upgrade Django to version 1.4.8, 1.5.4, or newer.
Which versions of Django are affected by CVE-2013-1443?
CVE-2013-1443 affects Django versions 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4.
What type of attack can exploit CVE-2013-1443?
CVE-2013-1443 can be exploited through a denial of service attack by sending a long password that consumes CPU resources.
Is there a workaround for CVE-2013-1443?
There is no direct workaround for CVE-2013-1443; upgrading to the patched version is recommended.