PublicDateAtUSN: 2019-12-18 Candidate: CVE-2019-19844 PublicDate: 2019-12-18 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19844 https://www.djangoproject.com/weblog/2019/dec/18/security-releases/ https://ubuntu.com/security/notices/USN-4224-1 Description: Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.) Ubuntu-Description: Notes: Mitigation: Bugs: Priority: high Discovered-by: Simon Charette Assigned-to: sbeattie CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_python-django: upstream: https://github.com/django/django/commit/f4cff43bf921fcea6a29b726eb66767f67753fa2 (1.11.x) upstream: https://github.com/django/django/commit/4d334bea06cac63dc1272abcec545b85136cca0e (2.2.x) upstream_python-django: released (1.11.27, 2.2.9) precise/esm_python-django: DNE trusty_python-django: ignored (out of standard support) trusty/esm_python-django: needs-triage xenial_python-django: released (1.8.7-1ubuntu5.11) esm-infra/xenial_python-django: released (1.8.7-1ubuntu5.11) bionic_python-django: released (1:1.11.11-1ubuntu1.6) disco_python-django: released (1:1.11.20-1ubuntu0.3) eoan_python-django: released (1:1.11.22-1ubuntu1.1) devel_python-django: released (2:2.2.9-2ubuntu1)