Vulnerabilidades en djust-org
13 resultadosAnálisis Vexday
O fornecedor djust-org apresenta footprint reduzido com apenas 1 CVE registrado, sem incidentes de exploração ativa conhecida. A vulnerabilidade, publicada recentemente (últimos 90 dias) e classificada como autorização imprópria (CWE-285), não alcança severidade crítica, mantendo o risco em nível controlado mas requerendo atenção ao seu caráter recente.
CVE-2026-61594CRITICALdjust has an authorization bypass on the WebSocket/SSE mount pathEPSS 0.4%CVE-2026-61598HIGHClient mass-assignment of arbitrary view attributes via the default dj-model update_model handlerEPSS 0.4%CVE-2026-61595HIGHdjust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' dataEPSS 0.4%CVE-2026-61599HIGHdjust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount pathEPSS 0.4%CVE-2026-61590HIGHdjust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUGEPSS 0.3%CVE-2026-61597MEDIUMdjust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tagsEPSS 0.3%CVE-2026-61588MEDIUMdjust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the clientEPSS 0.3%CVE-2026-61592HIGHdjust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)EPSS 0.3%CVE-2026-55571HIGHdjust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler callsEPSS 0.3%CVE-2026-61596HIGHdjust has broken object-level access control (IDOR)EPSS 0.2%CVE-2026-61593HIGHdjust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE sessionEPSS 0.2%CVE-2026-61591HIGHdjust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)EPSS 0.2%CVE-2026-61589MEDIUMdjust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live pathEPSS 0.2%