CVE-2024-21543
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.7epss 0.5%
exploitation probability
0.5%top 55% of all CVEs
observed exploitation
nono source reports it
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor authentication, LDAP validations, or requirements from configured AUTHENTICATION_BACKENDS.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
n/a · djoserReferences
https://github.com/sunscrapers/djoser/commit/d33c3993c0c735f23cbedc60fa59fce69354f19dhttps://github.com/sunscrapers/djoser/issues/795https://github.com/sunscrapers/djoser/pull/819https://github.com/sunscrapers/djoser/releases/tag/2.3.0https://lists.debian.org/debian-lts-announce/2025/02/msg00023.htmlhttps://security.snyk.io/vuln/SNYK-PYTHON-DJOSER-8366540