drf-jwt
JSON Web Token based authentication for Django REST framework
Activity
- Latest release
- 4y ago
- Total releases
- 24
- Cadence
- ~25 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Dec 13, 2018
Releases
| Version | Released | |
|---|---|---|
1.19.2
patch
| ||
1.19.1
patch
| ||
1.19.0
minor
| ||
1.18.0
minor
| ||
1.17.3
patch
| ||
1.17.2
patch
| ||
1.17.1
patch
| ||
1.17.0
minor
| ||
1.16.2
patch
| ||
1.16.1
patch
| ||
1.16.0
minor
| ||
1.15.2
patch
| ||
1.15.1
patch
| ||
1.15.0
minor
1 CVE
CVE-2020-10594
GHSA-fpjm-rp2g-3r4c
PYSEC-2020-40
Jun 05, 2020
Django Rest Framework jwt allows obtaining new token from notionally invalidated token
Critical
Network
Low
None
None
An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of jpadilla/django-rest-framework-jwt, which is unmaintained. Affected versions
1.15.0
Fixed in
1.15.1
References
Updated Feb 21, 2025 · Source: OSV.dev | ||
1.14.0
minor
| ||
1.13.4
patch
| ||
1.13.3
patch
| ||
1.13.2
patch
| ||
1.13.1
patch
| ||
1.13.0
minor
| ||
1.12.10
patch
| ||
1.12.8
patch
| ||
1.12.7
patch
| ||
1.12.3
initial
|