Name | CVE-2024-22513 |
Description | djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 1067641 |
Vulnerable and fixed packages
The table below lists information on source packages.
The information below is based on the following data on fixed versions.
Notes
https://github.com/dmdhrumilmistry/CVEs/tree/main/CVE-2024-22513
https://github.com/jazzband/djangorestframework-simplejwt/issues/805
https://github.com/jazzband/djangorestframework-simplejwt/issues/779
Questionable CVE: This is an insecure interface, not a vulnerability per se