vendor:
djangorestframework-simplejwt
by:
Dhrumil Mistry
6.1
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: djangorestframework-simplejwt
Affected Version From: 5.3.2001
Affected Version To: 5.3.2001
Patch Exists: NO
Related CWE: CVE-2024-22513
CPE: a:jazzband:djangorestframework-simplejwt:5.3.1
Platforms Tested: MacOS
2024
djangorestframework-simplejwt 5.3.1 – Information Disclosure
A vulnerability in djangorestframework-simplejwt version <= 5.3.1 allows for various security issues such as Business Object Level Authorization (BOLA), Business Function Level Authorization (BFLA), and Information Disclosure. This vulnerability permits users to access web application resources even after their account has been deactivated due to inadequate user validation checks.
Mitigation:
To mitigate this vulnerability, users are advised to update to a version of djangorestframework-simplejwt above 5.3.1 where the issue has been resolved.