216.73.216.197

CVE-2024-39329

· Published 10/07/2024 05:15 · Modified 10/07/2024 05:15

Labels: CVE-2024-39329 2024-07-10CVE-2024-39329[email protected]

Essential information

Published
10/07/2024 05:15
Modified
10/07/2024 05:15
Author
Creator
CISA KEV
No
CWE

Description

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for users with an unusable password.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References