CVE-2018-6188: Infoleak
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirmloginallowed() method, as demonstrated by discovering whether a user account is inactive.
Other sources
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirmloginallowed() method, as demonstrated by discovering whether a user account is inactive.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Djangoto a version that resolves this vulnerability.Fixed in 2.0.2 - Upgrade
Upgrade
pip/djangoto a version that resolves this vulnerability.Fixed in 1.11.10 - Upgrade
Upgrade
debian/python-djangoto a version that resolves this vulnerability.Fixed in 2:2.2.28-1~deb11u2Fixed in 2:2.2.28-1~deb11u12Fixed in 3:3.2.25-0+deb12u3Fixed in 3:3.2.25-0+deb12u2Fixed in 3:4.2.28-0+deb13u2Fixed in 3:4.2.28-0+deb13u1Fixed in 3:5.2.16-1 - Upgrade
Upgrade
django.contrib.auth.forms.AuthenticationFormto a version that resolves this vulnerability.Fixed in 2.0.2 - Upgrade
Upgrade
django.contrib.auth.forms.AuthenticationFormto a version that resolves this vulnerability.Fixed in 1.11.10
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6188?
The severity of CVE-2018-6188 is high with a CVSS score of 7.5.
How does CVE-2018-6188 affect Django?
CVE-2018-6188 affects Django versions 1.11.8, 1.11.9, 2.0 before 2.0.2.
How can remote attackers exploit CVE-2018-6188?
Remote attackers can exploit CVE-2018-6188 by leveraging data exposure from the confirm_login_allowed() method in django.contrib.auth.forms.AuthenticationForm to obtain potentially sensitive information.
Which versions of Django are affected by CVE-2018-6188?
Django versions 1.11.8, 1.11.9, 2.0 before 2.0.2 are affected by CVE-2018-6188.
How do I fix CVE-2018-6188?
To fix CVE-2018-6188, update Django to version 1.11.10 for versions 1.11.8 and 1.11.9, or update to version 2.0.2 for versions 2.0 before 2.0.2.