django-allauth is vulnerable to Cross-Site Request Forgery and Open Redirect
60
Medium Risk
Affected versions of django-allauth are vulnerable to cross-site request forgery (CSRF) and open redirect. Both IdP-initiated and SP-initiated SSO flows were susceptible to this attack. The IdP-initiated SSO flow is now disabled by default in the patched version.
You are affected if you are using a vulnerable version of the package.
django-allauth is vulnerable to Cross-Site Request Forgery and Open Redirect in versions 0.1.0 - 0.63.2.
Upgrade django-allauth to the patch version (0.63.3).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant