GHSA-mwv2-398h-v489

Suggest an improvement
Source
https://github.com/advisories/GHSA-mwv2-398h-v489
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mwv2-398h-v489/GHSA-mwv2-398h-v489.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-mwv2-398h-v489
Aliases
Published
2022-05-01T17:44:04Z
Modified
2024-05-23T16:40:37Z
Summary
Django Improper Access Control
Details

The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.

Database specific
{
    "nvd_published_at": "2007-01-23T00:28:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-14T17:18:53Z"
}
References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.95
Fixed
1.0

Affected versions

0.*

0.95