Your submission was sent successfully! Close

CVE-2019-19844

Published: 18 December 2019

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

Priority

High

CVSS 3 base score: 9.8

Status

Package Release Status
python-django
Launchpad, Ubuntu, Debian
bionic
Released (1:1.11.11-1ubuntu1.6)
disco
Released (1:1.11.20-1ubuntu0.3)
eoan
Released (1:1.11.22-1ubuntu1.1)
precise Does not exist

trusty Needs triage

upstream
Released (1.11.27, 2.2.9)
xenial
Released (1.8.7-1ubuntu5.11)