CVE-2018-6188: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 4.8% chance of exploitation in the next 30 days.
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.
Affected products
- Canonical Ubuntu Linux: version 17.10 only
- Djangoproject Django: version 1.11.8 only; version 1.11.9 only; version 2.0 only; version 2.0.1 only
Published 2018-02-05. Last modified 2026-06-17.