9.8

CVE-2019-19844

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Djangoproject ≫ Django Version < 1.11.27
Djangoproject ≫ Django Version >= 2.2 < 2.2.9
Djangoproject ≫ Django Version 3.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Canonical ≫ Ubuntu Linux Version 19.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 35.05% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-640 Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

https://docs.djangoproject.com/en/dev/releases/security/
Vendor Advisory
https://security.gentoo.org/glsa/202004-17
http://packetstormsecurity.com/files/155872/Django-Account-Hijack.html
https://groups.google.com/forum/#%21topic/django-announce/3oaB2rVH3a0
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCM2DPUI7TOZWN4A6JFQFUVQ2XGE7GUD/
https://seclists.org/bugtraq/2020/Jan/9
https://security.netapp.com/advisory/ntap-20200110-0003/
https://usn.ubuntu.com/4224-1/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4598
https://www.djangoproject.com/weblog/2019/dec/18/security-releases/
Vendor Advisory