PT-2026-61041 · Pypi · Django Tastypie
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
django-tastypie versions prior to 0.15.2
Description
An information disclosure issue exists in the
ApiKeyAuthentication() function within the tastypie/authentication.py file. A remote attacker can manipulate the system to use the GET request method with sensitive query strings, potentially exposing confidential data. This attack is characterized by high complexity and is considered difficult to exploit.Recommendations
As a temporary workaround, restrict the use of the
ApiKeyAuthentication() function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django Tastypie