REDHAT-BUG-2295936: Low severity Django Django vulnerability
The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for users with unusable passwords.
Affected versions =================
Django main development branch Django 5.1 Django 5.0 Django 4.2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2295936?
The vulnerability REDHAT-BUG-2295936 is classified as a medium severity timing attack that permits user enumeration.
How do I fix REDHAT-BUG-2295936?
To address REDHAT-BUG-2295936, it's recommended to upgrade Django to a version that has patched the vulnerability.
Who is affected by REDHAT-BUG-2295936?
Any applications utilizing Django versions up to 5.1 that employ the ModelBackend for authentication are affected by REDHAT-BUG-2295936.
What types of attacks does REDHAT-BUG-2295936 facilitate?
REDHAT-BUG-2295936 allows remote attackers to exploit timing discrepancies to enumerate valid usernames through login attempts.
Is there a workaround for REDHAT-BUG-2295936?
Currently, there is no official workaround for REDHAT-BUG-2295936 besides upgrading to a secured version of Django.