CVE-2018-6188: Information Exposure
(updated )
django.contrib.auth.forms.AuthenticationForm
allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed()
method, as demonstrated by discovering whether a user account is inactive.
References
Detect and mitigate CVE-2018-6188 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →