Bug 2269822 (CVE-2024-22513) - CVE-2024-22513 djangorestframework-simplejwt: information disclosure vulnerability
Summary: CVE-2024-22513 djangorestframework-simplejwt: information disclosure vulnerab...
Keywords:
Status: NEW
Alias: CVE-2024-22513
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2269828
TreeView+ depends on / blocked
 
Reported: 2024-03-16 17:52 UTC by Avinash Hanwate
Modified: 2024-04-16 08:58 UTC (History)
13 users (show)

Fixed In Version:
Doc Type: ---
Doc Text:
A flaw was found in djangorestframework-simplejwt. Affected versions of this package are vulnerable to information disclosure. This flaw allows a user to access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2024-03-16 17:52:12 UTC
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.

https://github.com/dmdhrumilmistry/CVEs/tree/main/CVE-2024-22513


Note You need to log in before you can comment on or make changes to this bug.