django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) fo…
Low CVSS 3.7
Summary
django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96
- https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83
- https://codeberg.org/allauth/django-allauth/commit/ae472772c8f93bcb972205c9d7159051cf6f413a
- https://docs.allauth.org/en/latest/release-notes/recent.html
- https://pypi.org/project/django-allauth/
Timeline
- nvd_ingest NVD