HomeDefectsLIN1021-10195
Acknowledged

LIN1021-10195 : Security Advisory - python-django - CVE-2024-39329

Created: Jul 9, 2024    Updated: Jan 28, 2026
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for users with an unusable password.

https://nvd.nist.gov/vuln/detail/CVE-2024-39329