Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-21543

Опубликовано: 13 дек. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.1

Описание

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

РелизСтатусПримечание
devel

not-affected

2.3.1-1
esm-apps/bionic

not-affected

code not present
esm-apps/focal

released

2.0.3-1ubuntu0.1~esm1
esm-apps/jammy

released

2.1.0-1ubuntu0.22.04.1
esm-apps/noble

released

2.1.0-1ubuntu0.24.04.1
esm-apps/xenial

not-affected

code not present
focal

ignored

end of standard support, was needed
jammy

released

2.1.0-1ubuntu0.22.04.1
noble

released

2.1.0-1ubuntu0.24.04.1
oracular

released

2.1.0-1ubuntu0.24.10.1

Показывать по

EPSS

Процентиль: 29%
0.00105
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
около 1 года назад

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

CVSS3: 7.1
debian
около 1 года назад

Versions of the package djoser before 2.3.0 are vulnerable to Authenti ...

CVSS3: 7.1
github
около 1 года назад

djoser Authentication Bypass

EPSS

Процентиль: 29%
0.00105
Низкий

7.1 High

CVSS3