Information Exposure Through an Error Message in Django - CVE-2024-45231

 

Information Exposure Through an Error Message in Django - CVE-2024-45231

Published: September 3, 2024


Vulnerability identifier: #VU96743
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45231
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to enumerate email addresses.

The vulnerability exists due to an error when handling password reset in django.contrib.auth.forms.PasswordResetForm. A remote attacker can enumerate user email addresses.


Affected software

Django
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Oracle Solaris
Maximo Application Suite - Edge Data Collector
python3-django (Ubuntu package)
python-django (Ubuntu package)
python3-Django
python-django-help
python-django
python-django (Debian package)
python311-Django
dev-python/django

How to mitigate CVE-2024-45231

Install updates from vendor's website.

Django - addressed in versions 4.2.16, 5.0.9, 5.1.1
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.14, 9.0.6, 9.1.0
python3-django (Ubuntu package) - addressed in versions Ubuntu Pro, 2:2.2.12-1ubuntu0.25, 2:3.2.12-2ubuntu1.14, 3:4.2.11-1ubuntu1.3
python-django (Ubuntu package) - update to Ubuntu Pro
python3-Django - update to 2.0.7-150000.1.33.1
python3-Django - addressed in versions 2.2.27-12, 4.2.15-2
python-django-help - addressed in versions 2.2.27-12, 4.2.15-2
python-django - addressed in versions 2.2.27-12, 4.2.15-2
python-django (Debian package) - update to 3:3.2.25-0+deb12u1
python311-Django - update to 4.2.11-150600.3.9.1
dev-python/django - update to 5.2.1
Oracle Solaris - update to 11.4 SRU 74

External References

Related Security Bulletins