Loading HuntDB...

GHSA-v49p-m6gh-747c

GitHub Security Advisory

djoser Authentication Bypass

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.

Affected Packages

PyPI djoser
Affected versions: 0 (fixed in 2.3.0)

Related CVEs

Key Information

GHSA ID
GHSA-v49p-m6gh-747c
Published
December 13, 2024 6:30 AM
Last Modified
February 21, 2025 4:08 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
djoser
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 13, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.