296,147
Total vulnerabilities in the database
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.
Software | From | Fixed in |
---|---|---|
djangoproject / django | 2.0 | 2.0.x |
djangoproject / django | 2.0.1 | 2.0.1.x |
djangoproject / django | 1.11.8 | 1.11.8.x |
djangoproject / django | 1.11.9 | 1.11.9.x |
canonical / ubuntu_linux | 17.10 | 17.10.x |
![]() |
2.0.0 | 2.0.2 |
![]() |
1.11.8 | 1.11.10 |