Ubuntu Security Notice 6722-1 - Simon Charette discovered that the password reset functionality in Django used a Unicode case insensitive query to retrieve accounts associated with an email address. An attacker could possibly use this to obtain password reset tokens and hijack accounts.
3549b31155b113a63c6896dc127bcb848e03f8f2acb9aedc5c6399efc9f1b5e5
Gentoo Linux Security Advisory 202004-17 - Multiple vulnerabilities have been found in Django, the worst of which could result in privilege escalation. Versions less than 2.2.11 are affected.
4a2831d98946075ac9b91d6bed2f78491188825a08f52e9e12c28e2ed15084a5
Debian Linux Security Advisory 4598-1 - Simon Charette reported that the password reset functionality in Django, a high-level Python web development framework, uses a Unicode case-insensitive query to retrieve accounts matching the email address requesting the password reset. An attacker can take advantage of this flaw to potentially retrieve password reset tokens and hijack accounts.
f5673ae929ba17e846a9995b9d5afe651944e292787ae289f570b05b3e483a97
Django versions prior to 3.0, 2.2, and 1.11 account hijack proof of concept exploit.
09c0f50e3a8e55f9ff1ddd09386d4e27b175f680162cb0b2fda29e9cca3ed4b9
Ubuntu Security Notice 4224-1 - Simon Charette discovered that the password reset functionality in Django used a Unicode case insensitive query to retrieve accounts associated with an email address. An attacker could possibly use this to obtain password reset tokens and hijack accounts.
2d00245a2e8b66cfc557ff1fb2cb66b61f72d82bf26c36911ca948106d412ecb