CVE-2018-6188

Impact:
Moderate
CWE:
CWE-209
Bugzilla:
1538793: CVE-2018-6188 django: Information leakage in AuthenticationForm

The MITRE CVE dictionary describes this issue as:

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.

Find out more about CVE-2018-6188 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue affects the versions of python-django as shipped with Red Hat Satellite version 6. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

This issue affects the versions of python-django as shipped with Red Hat Subscription Asset Manager version 1. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 5.3
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact None
Availability Impact None

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 Django Will not fix
Red Hat Storage Console 2 python-django Not affected
Red Hat Satellite 6 python-django Will not fix
Red Hat OpenStack Platform Operational Tools 9 python-django Not affected
Red Hat OpenStack Platform 9.0 python-django Not affected
Red Hat OpenStack Platform 8.0 (Liberty) python-django Not affected
Red Hat OpenStack Platform 13.0 (Queens) python-django Not affected
Red Hat OpenStack Platform 12.0 python-django Not affected
Red Hat OpenStack Platform 11.0 (Ocata) python-django Not affected
Red Hat OpenStack Platform 10 python-django Not affected
Red Hat Gluster Storage 3 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 8.0 Operational Tools for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 python-django Not affected
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 python-django Not affected
Red Hat Ceph Storage 3 python-django Not affected
Red Hat Ceph Storage 2 Django Not affected
Red Hat Ceph Storage 1.3 Django Not affected

External References

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.