Vulnerabilities
Last updated 40 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path | Medium Risk 6.3 | 14 days ago | 2 hours ago |
|
|
djust: A template binding inherits a context safety grant it never earned (XSS) | High Risk 8.0 | 13 days ago | 13 days ago |
|
|
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS) | High Risk 8.0 | 13 days ago | 13 days ago |
|
|
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path | High Risk 8.0 | 14 days ago | 14 days ago |
|
|
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection) | High Risk 8.1 | 14 days ago | 14 days ago |
|
|
djust has broken object-level access control (IDOR) | High Risk 7.1 | 14 days ago | 14 days ago |
|
|
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client | Medium Risk 6.5 | 14 days ago | 14 days ago |
|
|
djust has an authorization bypass on the WebSocket/SSE mount path | Critical 9.1 | 14 days ago | 14 days ago |
|
|
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags | Medium Risk 6.0 | 14 days ago | 14 days ago |
|
|
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack) | High Risk 7.4 | 14 days ago | 14 days ago |
|
|
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session | High Risk 8.1 | 15 days ago | 15 days ago |
|
|
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data | High Risk 7.7 | 15 days ago | 15 days ago |
|
|
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler | High Risk 8.0 | 15 days ago | 15 days ago |
|
|
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG | High Risk 7.4 | 15 days ago | 15 days ago |
|
|
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls | High Risk 8.2 | 1 month ago | 21 days ago |
|
|
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls | High Risk 8.2 | 21 days ago | 21 days ago |
|
|
Malicious code in @antv/adjust (npm) | Unknown | 4 months ago | 2 months ago |
|
|
Malicious code in bk-card-cc-credit-limit-adjustment-ui (npm) | Unknown | 1 year ago | 1 year ago |
|
|
Malicious code in com.adjust.test (npm) | Unknown | 1 year ago | 1 year ago |
|
|
Malicious code in viewportpriorityadjuster (npm) | Unknown | 4 years ago | 2 years ago |
|
|
Malicious code in firstloadedvideopriorityadjuster (npm) | Unknown | 4 years ago | 2 years ago |
Page 1