Authentication mechanism absence or evasion In django-allauth
Description
django-allauth does not reject access tokens for inactive users An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
debian 13 | - | ||
debian 14 | 65.15.0-1 | ||
debian 12 | - | ||
pypi | 65.13.0 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.