Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v49p-m6gh-747c

Опубликовано: 13 дек. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 7.1

Описание

djoser Authentication Bypass

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

Пакеты

Наименование

djoser

pip
Затронутые версииВерсия исправления

< 2.3.0

2.3.0

EPSS

Процентиль: 29%
0.00105
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-287
CWE-295

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 года назад

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

CVSS3: 7.1
nvd
около 1 года назад

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

CVSS3: 7.1
debian
около 1 года назад

Versions of the package djoser before 2.3.0 are vulnerable to Authenti ...

EPSS

Процентиль: 29%
0.00105
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-287
CWE-295