django-oauth-toolkit is vulnerable to Authorization Logic Flaws
71
High Risk
This release fixes multiple security issues in django-oauth-toolkit, including an OAuth device-flow authorization flaw where missing scope could lead to device code tokens receiving incorrect/default scopes (scope escalation). It also standardizes device grant model usage via get_device_grant_model() to prevent incorrect grant handling, and includes a DoS mitigation for the RefreshToken admin changelist plus a fix to the JWKS endpoint cache header.
You are affected if you are using a version that falls within the vulnerable range.
django-oauth-toolkit is vulnerable to Authorization Logic Flaws in versions 0.0.1 - 3.2.0.
Upgrade the django-oauth-toolkit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant