CVE-2016-2513 PUBLISHED

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

EPSS 1.25% · 79.2th percentile

Risk Scores

EPSS Score
1.25%
79.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSpython-django1.6-1, 1.6.1-1, 1.6.1-2ubuntu0.1

Timeline

References

Open in Interactive Console →