CVE-2020-10594
Summary
| CVE | CVE-2020-10594 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-15 22:15:00 UTC |
| Updated | 2020-03-19 17:38:00 UTC |
| Description | An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of jpadilla/django-rest-framework-jwt, which is unmaintained. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Blacklisted tokens can still be refreshed · Issue #36 · Styria-Digital/django-rest-framework-jwt · GitHub |
MISC |
github.com |
Issue Tracking, Third Party Advisory |
| drf-jwt · PyPI |
MISC |
pypi.org |
Release Notes, Third Party Advisory |
| Status · Issue #484 · jpadilla/django-rest-framework-jwt · GitHub |
MISC |
github.com |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981478 Python (pip) Security Update for drf-jwt (GHSA-fpjm-rp2g-3r4c)