djoser
REST implementation of Django authentication system.
Activity
- Latest release
- 1mo ago
- Total releases
- 52
- Cadence
- ~21 days
- Last 12 months
- 2
Reach
- Stars
- 2.7k
Details
- License
- MIT
- First release
- Oct 07, 2014
| Version | Released | |
|---|---|---|
2.3.4
patch
| ||
2.3.4a1
pre
| ||
2.3.3
patch
| ||
2.3.2
patch
| ||
2.3.1
patch
| ||
2.3.0
minor
| ||
2.2.3
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.2.2
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.2.0a0
pre
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev |
2.1.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.0.5
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.5.1
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.4.1
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.3.3
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.2.2
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.1.5
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.1.4
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.1.3
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.1.2
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.5.4
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.5.3
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.5.2
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.1.0
minor
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
0.0.3
patch
1 CVE
CVE-2024-21543
GHSA-v49p-m6gh-747c
PYSEC-2024-158
Dec 13, 2024
djoser Authentication Bypass
High
Network
Low
Low
None
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS. Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
+ 34 more Show less
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.7.0
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.2
1.3.3
1.4.1
1.5.1
1.6.0
1.7.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.0a0
2.2.1
2.2.2
2.2.3
Fixed in
2.3.0
References
Updated Feb 21, 2025 · Source: OSV.dev |