github.com
https://github.com/dmdhrumilmistry/CVEs/tree/main/CVE-2024-22513 CVE-2024-22513
MEDIUM
Improper Privilege Management in djangorestframework-simplejwt
Record summary
CVE-2024-22513 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.
Description
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 18, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
djangorestframework-simplejwtBrowse PyPI / djangorestframework-simplejwt | GitHub Advisory | Before 5.5.1 · Fixed in 5.5.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBdjangorestframework-simplejwt 5.3.1 - Information DisclosureExploitDB exploitby Dhrumil MistryNot analyzed1 file
References
11github.com
https://github.com/jazzband/djangorestframework-simplejwt github.com
https://github.com/jazzband/djangorestframework-simplejwt/blob/c791e987332ed5e22a86428160d6372b1d85ffae/rest_framework_simplejwt/tokens.py github.com
https://github.com/jazzband/djangorestframework-simplejwt/commit/14e8b2cf5fa0df954af82ff3926fa6d6c4ecf13e github.com
https://github.com/jazzband/djangorestframework-simplejwt/commit/1ad763bfe73936515aa4756263338c63866364c9 github.com
https://github.com/jazzband/djangorestframework-simplejwt/commit/a2d0a0201b6123536ecf76cd4d0ec7389317d0a7 github.com
https://github.com/jazzband/djangorestframework-simplejwt/issues/779 github.com
https://github.com/jazzband/djangorestframework-simplejwt/pull/872 github.com
https://github.com/jazzband/djangorestframework-simplejwt/pull/873 github.com
https://github.com/jazzband/djangorestframework-simplejwt/pull/891 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-22513