Commit 22b74fa
committed
[1.5.x] Ensure that passwords are never long enough for a DoS.
* Limit the password length to 4096 bytes
* Password hashers will raise a ValueError
* django.contrib.auth forms will fail validation
* Document in release notes that this is a backwards incompatible change
Thanks to Josh Wright for the report, and Donald Stufft for the patch.
This is a security fix; disclosure to follow shortly.
Backport of aae5a96 from master.1 parent e66fe35 commit 22b74fa
3 files changed
Lines changed: 134 additions & 15 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
16 | 18 | | |
17 | 19 | | |
18 | 20 | | |
| |||
75 | 77 | | |
76 | 78 | | |
77 | 79 | | |
78 | | - | |
| 80 | + | |
79 | 81 | | |
80 | 82 | | |
| 83 | + | |
81 | 84 | | |
82 | 85 | | |
83 | 86 | | |
| |||
145 | 148 | | |
146 | 149 | | |
147 | 150 | | |
148 | | - | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
149 | 156 | | |
150 | 157 | | |
151 | 158 | | |
| |||
269 | 276 | | |
270 | 277 | | |
271 | 278 | | |
272 | | - | |
273 | | - | |
274 | | - | |
275 | | - | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
276 | 289 | | |
277 | 290 | | |
278 | 291 | | |
| |||
303 | 316 | | |
304 | 317 | | |
305 | 318 | | |
306 | | - | |
307 | | - | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
308 | 324 | | |
309 | 325 | | |
310 | 326 | | |
| |||
329 | 345 | | |
330 | 346 | | |
331 | 347 | | |
332 | | - | |
333 | | - | |
334 | | - | |
335 | | - | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
336 | 358 | | |
337 | 359 | | |
338 | 360 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
16 | 17 | | |
17 | 18 | | |
18 | 19 | | |
| 20 | + | |
19 | 21 | | |
20 | 22 | | |
21 | 23 | | |
| |||
27 | 29 | | |
28 | 30 | | |
29 | 31 | | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
30 | 44 | | |
31 | 45 | | |
32 | 46 | | |
| |||
225 | 239 | | |
226 | 240 | | |
227 | 241 | | |
| 242 | + | |
228 | 243 | | |
229 | 244 | | |
230 | 245 | | |
| |||
234 | 249 | | |
235 | 250 | | |
236 | 251 | | |
| 252 | + | |
237 | 253 | | |
238 | 254 | | |
239 | 255 | | |
| |||
279 | 295 | | |
280 | 296 | | |
281 | 297 | | |
| 298 | + | |
282 | 299 | | |
283 | 300 | | |
284 | 301 | | |
285 | 302 | | |
286 | 303 | | |
287 | 304 | | |
288 | 305 | | |
| 306 | + | |
289 | 307 | | |
290 | 308 | | |
291 | 309 | | |
| |||
310 | 328 | | |
311 | 329 | | |
312 | 330 | | |
| 331 | + | |
313 | 332 | | |
314 | 333 | | |
315 | 334 | | |
316 | 335 | | |
317 | 336 | | |
318 | 337 | | |
| 338 | + | |
319 | 339 | | |
320 | 340 | | |
321 | 341 | | |
| |||
338 | 358 | | |
339 | 359 | | |
340 | 360 | | |
| 361 | + | |
341 | 362 | | |
342 | 363 | | |
343 | 364 | | |
344 | 365 | | |
345 | 366 | | |
346 | 367 | | |
| 368 | + | |
347 | 369 | | |
348 | 370 | | |
349 | 371 | | |
| |||
374 | 396 | | |
375 | 397 | | |
376 | 398 | | |
| 399 | + | |
377 | 400 | | |
378 | 401 | | |
379 | 402 | | |
380 | 403 | | |
381 | 404 | | |
| 405 | + | |
382 | 406 | | |
383 | 407 | | |
384 | 408 | | |
| |||
408 | 432 | | |
409 | 433 | | |
410 | 434 | | |
| 435 | + | |
411 | 436 | | |
412 | 437 | | |
413 | 438 | | |
414 | 439 | | |
| 440 | + | |
415 | 441 | | |
416 | 442 | | |
417 | 443 | | |
| |||
437 | 463 | | |
438 | 464 | | |
439 | 465 | | |
| 466 | + | |
440 | 467 | | |
441 | 468 | | |
442 | 469 | | |
443 | 470 | | |
444 | 471 | | |
445 | 472 | | |
446 | 473 | | |
| 474 | + | |
447 | 475 | | |
448 | 476 | | |
449 | 477 | | |
| |||
458 | 486 | | |
459 | 487 | | |
460 | 488 | | |
461 | | - | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
| 8 | + | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| |||
31 | 32 | | |
32 | 33 | | |
33 | 34 | | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
34 | 41 | | |
35 | 42 | | |
36 | 43 | | |
| |||
40 | 47 | | |
41 | 48 | | |
42 | 49 | | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
43 | 58 | | |
44 | 59 | | |
45 | 60 | | |
| |||
49 | 64 | | |
50 | 65 | | |
51 | 66 | | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
52 | 75 | | |
53 | 76 | | |
54 | 77 | | |
| |||
58 | 81 | | |
59 | 82 | | |
60 | 83 | | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
61 | 92 | | |
62 | 93 | | |
63 | 94 | | |
| |||
71 | 102 | | |
72 | 103 | | |
73 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
74 | 113 | | |
75 | 114 | | |
76 | 115 | | |
| |||
82 | 121 | | |
83 | 122 | | |
84 | 123 | | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
85 | 132 | | |
86 | 133 | | |
87 | 134 | | |
| |||
91 | 138 | | |
92 | 139 | | |
93 | 140 | | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
94 | 149 | | |
95 | 150 | | |
96 | 151 | | |
| |||
100 | 155 | | |
101 | 156 | | |
102 | 157 | | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
103 | 165 | | |
104 | 166 | | |
105 | 167 | | |
| |||
121 | 183 | | |
122 | 184 | | |
123 | 185 | | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
124 | 194 | | |
125 | 195 | | |
126 | 196 | | |
| |||
0 commit comments