Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpjm-rp2g-3r4c

Опубликовано: 05 июн. 2020
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

Django Rest Framework jwt allows obtaining new token from notionally invalidated token

An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of jpadilla/django-rest-framework-jwt, which is unmaintained.

Пакеты

Наименование

drf-jwt

pip
Затронутые версииВерсия исправления

>= 1.15.0, < 1.15.1

1.15.1

EPSS

Процентиль: 58%
0.00368
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
nvd
почти 6 лет назад

An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of jpadilla/django-rest-framework-jwt, which is unmaintained.

EPSS

Процентиль: 58%
0.00368
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-287