Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21543

Опубликовано: 13 дек. 2024
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

EPSS

Процентиль: 37%
0.00159
Низкий

7.1 High

CVSS3

Дефекты

CWE-287
CWE-295

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 года назад

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

CVSS3: 7.1
debian
около 1 года назад

Versions of the package djoser before 2.3.0 are vulnerable to Authenti ...

CVSS3: 7.1
github
около 1 года назад

djoser Authentication Bypass

EPSS

Процентиль: 37%
0.00159
Низкий

7.1 High

CVSS3

Дефекты

CWE-287
CWE-295