{"schema_version":"1.7.5","id":"CVE-2018-6188","published":"2018-02-05T03:29:00.267Z","modified":"2026-07-15T10:14:48.149789625Z","aliases":["GHSA-rf4j-j272-fj86","PYSEC-2018-4"],"related":["openSUSE-SU-2018:0632-1","openSUSE-SU-2023:0077-1","openSUSE-SU-2024:11205-1","openSUSE-SU-2024:13887-1","openSUSE-SU-2024:14208-1","openSUSE-SU-2026:10005-1","openSUSE-SU-2026:11235-1","openSUSE-SU-2026:11248-1","openSUSE-SU-2026:11270-1"],"details":"django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/django/django","events":[{"introduced":"dfe7b85ed7e0c46cb59f545a4eefa9c3fd629f7d"},{"last_affected":"7cc155a04ce9579de3cdca59db9a4de11dc5eab9"}],"database_specific":{"cpe":["cpe:2.3:a:djangoproject:django:1.11.8:*:*:*:*:*:*:*","cpe:2.3:a:djangoproject:django:1.11.9:*:*:*:*:*:*:*","cpe:2.3:a:djangoproject:django:2.0:*:*:*:*:*:*:*","cpe:2.3:a:djangoproject:django:2.0.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.11.8"},{"last_affected":"1.11.8"},{"introduced":"1.11.9"},{"last_affected":"1.11.9"},{"introduced":"2.0"},{"last_affected":"2.0"},{"introduced":"2.0.1"},{"last_affected":"2.0.1"}],"source":"CPE_STRING"}}],"versions":["1.11.8","1.11.9","2.0","2.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6188.json"}}],"references":[{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1040422"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3559-1/"},{"type":"FIX","url":"https://www.djangoproject.com/weblog/2018/feb/01/security-releases/"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"17.10"},{"last_affected":"17.10"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}