Re: [Django] #36651: Brute-force password attack against inactive users returns distinct error message (was: Security concerrn in ModelBackend)

1 view
Skip to first unread message

Django

unread,
Oct 9, 2025, 7:03:13 AM10/9/25
to django-...@googlegroups.com
#36651: Brute-force password attack against inactive users returns distinct error
message
-------------------------------------+-------------------------------------
Reporter: heindrickdumdum0217 | Owner: (none)
Type: Bug | Status: closed
Component: contrib.auth | Version: 5.2
Severity: Normal | Resolution: invalid
Keywords: | Triage Stage:
| Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-------------------------------------+-------------------------------------
Changes (by Jacob Walls):

* summary: Security concerrn in ModelBackend =>
Brute-force password attack against inactive users returns distinct
error message

--
Ticket URL: <https://code.djangoproject.com/ticket/36651#comment:3>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
Reply all
Reply to author
Forward
0 new messages