PT-2011-1594 · Django Software Foundation · Django

Luke Macken

·

Publicado

2011-01-10

·

Atualizado

2018-07-23

·

CVE-2010-4535

CVSS v4.0

6.6

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Django versions prior to 1.1.3 Django versions 1.2.x prior to 1.2.4 Django versions 1.3.x prior to 1.3 beta 1
Description The issue concerns the password reset functionality in django.contrib.auth. It does not validate the length of a string representing a base36 timestamp. This allows remote attackers to cause a denial of service via a URL that specifies a large base36 integer.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later. For versions 1.2.x prior to 1.2.4, update to version 1.2.4 or later. For versions 1.3.x prior to 1.3 beta 1, update to version 1.3 beta 1 or later.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4535
GHSA-7WPH-FC4W-WQP2
PYSEC-2011-29
PYSEC-2011-9

Produtos afetados

Django