PT-2026-61049 · Pypi · Django-Jet
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
django-jet versions prior to 1.0.9
Description
A missing authorization flaw exists in the OAuth Credential Revoke Handler component. This issue allows a remote attacker to perform a manipulation that bypasses authorization requirements.
Recommendations
Update to a version newer than 1.0.8.
Restrict access to the OAuth Credential Revoke Handler component to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Django-Jet