PYSEC-2013-18

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2013-18.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2013-18
Aliases
Published
2013-09-23T20:55:00Z
Modified
2023-11-01T05:44:25.323256Z
Summary
[none]
Details

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.4
Fixed
1.4.8
Introduced
1.5
Fixed
1.5.4

Affected versions

1.*

1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.5
1.5.1
1.5.2
1.5.3