django-allauth is vulnerable to Open Redirect
51
Medium Risk
Affected versions of this package are vulnerable to open redirect when SAML IdP-initiated single sign-on is enabled (default disabled). The application uses the RelayState parameter without proper validation, allowing an attacker to supply a crafted URL that redirects authenticated users to an external, attacker-controlled site after login.
You are affected if you are using a version that falls within the vulnerable range and SAML IdP-initiated single sign-on is enabled.
django-allauth is vulnerable to Open Redirect in versions 0.58.0 - 65.14.0.
Upgrade the django-allauth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant