==========================================================================
Ubuntu Security Notice USN-6722-1
April 08, 2024

python-django vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

Django accounts could be hijacked through password reset requests.

Software Description:
- python-django: High-level Python web development framework

Details:

Simon Charette discovered that the password reset functionality in
Django used a Unicode case insensitive query to retrieve accounts
associated with an email address. An attacker could possibly use this
to obtain password reset tokens and hijack accounts.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
   python-django                   1.6.11-0ubuntu1.3+esm7

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6722-1
   CVE-2019-19844

Ubuntu 6722-1: Django vulnerability

April 8, 2024
Django accounts could be hijacked through password reset requests.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Django accounts could be hijacked through password reset requests. Software Description: - python-django: High-level Python web development framework Details: Simon Charette discovered that the password reset functionality in Django used a Unicode case insensitive query to retrieve accounts associated with an email address. An attacker could possibly use this to obtain password reset tokens and hijack accounts.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS (Available with Ubuntu Pro): python-django 1.6.11-0ubuntu1.3+esm7 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6722-1

CVE-2019-19844

Severity
Ubuntu Security Notice USN-6722-1

Package Information

Related News