logo

CVE-2020-10594 drf-jwt

Package

Manager: pip
Name: drf-jwt
Vulnerable Version: >=1.15.0 <1.15.1

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00368 pctl0.57957

Details

Django Rest Framework jwt allows obtaining new token from notionally invalidated token An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of jpadilla/django-rest-framework-jwt, which is unmaintained.

Metadata

Created: 2020-06-05T16:09:34Z
Modified: 2024-09-20T17:05:27Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-fpjm-rp2g-3r4c/GHSA-fpjm-rp2g-3r4c.json
CWE IDs: ["CWE-287"]
Alternative ID: GHSA-fpjm-rp2g-3r4c
Finding: F039
Auto approve: 1