Intel

AIKIDO-2024-10115

django-allauth is vulnerable to Cross-Site Request Forgery and Open Redirect

Cross-Site Request Forgery and Open Redirect Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 4, 2024

60

Medium Risk

This Affects:

pythondjango-allauth
0.1.0 - 0.63.2
Fixed in 0.63.3
Are you affected? Scan for Free

TL;DR

Affected versions of django-allauth are vulnerable to cross-site request forgery (CSRF) and open redirect. Both IdP-initiated and SP-initiated SSO flows were susceptible to this attack. The IdP-initiated SSO flow is now disabled by default in the patched version.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

django-allauth is vulnerable to Cross-Site Request Forgery and Open Redirect in versions 0.1.0 - 0.63.2.

How to fix this

Upgrade django-allauth to the patch version (0.63.3).