django-guardian is vulnerable to Improper Authorization
70
High Risk
Affected versions of this package fail to properly enforce checks for guardian permissions, making both GuardedModelAdminMixin and GuardedModelAdmin unsafe. Any user who accesses the paths provided by GuardedModelAdminMixin can view, add, change, and delete guardian permissions for any user, regardless of whether the current user has the necessary guardian permissions. This vulnerability allows unauthorized users to manipulate permissions, potentially compromising the security and integrity of the system.
You are affected if you are using a version that falls within the vulnerable range.
django-guardian is vulnerable to Improper Authorization in versions 1.0.0 - 2.4.0.
Upgrade the django-guardian library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant