django-allauth is vulnerable to Authentication Bypass by Capture-replay
50
Medium Risk
Affected versions of the package are vulnerable to authentication bypass by capture-replay. When an ID token is used for authentication, the JTI (JWT ID) is now respected to prevent the possibility of replays, instead of solely relying on the expiration time.
You are affected if you are using a version that falls within the vulnerable range.
django-allauth is vulnerable to Authentication Bypass by Capture-replay in versions 0.61.1 - 64.1.0.
Upgrade the django-allauth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant