Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhmc-3mvr-f2j4

Опубликовано: 15 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

django-allauth does not reject access tokens for inactive users

An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.

Пакеты

Наименование

django-allauth

pip
Затронутые версииВерсия исправления

< 65.13.0

65.13.0

EPSS

Процентиль: 9%
0.00032
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 месяцев назад

An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.

CVSS3: 5.4
nvd
около 2 месяцев назад

An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.

CVSS3: 5.4
debian
около 2 месяцев назад

An issue was discovered in allauth-django before 65.13.0. IdP: marking ...

EPSS

Процентиль: 9%
0.00032
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-613