django-guardian is vulnerable to Improper Authorization
70
High Risk
Affected versions of this package fail to properly enforce checks for guardian permissions, making both GuardedModelAdminMixin and GuardedModelAdmin unsafe. Any user who accesses the paths provided by GuardedModelAdminMixin can view, add, change, and delete guardian permissions for any user, regardless of whether the current user has the necessary guardian permissions. This vulnerability allows unauthorized users to manipulate permissions, potentially compromising the security and integrity of the system.
You are affected if you are using a version that falls within the vulnerable range.
django-guardian is vulnerable to Improper Authorization in versions 1.0.0 - 2.4.0.
Upgrade the django-guardian library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant