{"id":"CVE-2024-45231","details":"An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).","aliases":["BIT-django-2024-45231","GHSA-rrqc-c2jx-6jgv","PYSEC-2026-1297"],"modified":"2026-07-11T09:29:26.155929037Z","published":"2024-10-08T00:00:00Z","related":["SUSE-SU-2024:3139-1","SUSE-SU-2024:3161-1","openSUSE-SU-2024:0282-1","openSUSE-SU-2024:14310-1","openSUSE-SU-2024:14318-1","openSUSE-SU-2026:10005-1","openSUSE-SU-2026:11235-1","openSUSE-SU-2026:11248-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45231.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://docs.djangoproject.com/en/dev/releases/security/"},{"type":"WEB","url":"https://groups.google.com/forum/#%21forum/django-announce"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45231.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45231"},{"type":"ARTICLE","url":"https://www.djangoproject.com/weblog/2024/sep/03/security-releases/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/django/django","events":[{"introduced":"0"},{"fixed":"6f9fea33137fee6416ff43b775aa9567440a23d3"},{"introduced":"52821001bb62b764d73e63812133f199b8fef9eb"},{"fixed":"8e68f938f376cf2ca22a7e8ff0bcbe1b7a5832d1"},{"introduced":"84d09a547fe35e10018ab242602ca76c29ca91a1"}],"database_specific":{"extracted_events":[{"introduced":"4.2.0"},{"fixed":"4.2.16"},{"introduced":"5.0"},{"fixed":"5.0.9"},{"introduced":"5.1"},{"last_affected":"5.1"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*","cpe:2.3:a:djangoproject:django:5.1:*:*:*:*:*:*:*"]}}],"versions":["5.1","4.2.15","5.0.8","5.0.7","4.2.14","5.0.6","4.2.13","4.2.12","5.0.5","5.0.4","4.2.11","5.0.3","4.2.10","5.0.2","4.2.9","5.0.1","5.0","4.2.8","5.0rc1","4.2.7","5.0b1","4.2.6","5.0a1","4.2.5","4.2.4","4.2.3","4.2.2","4.2.1","4.2","4.2rc1","4.2b1","4.2a1","1.7a2","1.4","1.3","1.2.1","1.2","1.1","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45231.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}