django-hashid-field@1.2.3 vulnerabilities

A Hashids obfuscated Django Model Field

  • latest version

    3.4.1

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the django-hashid-field package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Access Restriction Bypass

    django-hashid-field is an A Hashids obfuscated Django Model Field.

    Affected versions of this package are vulnerable to Access Restriction Bypass. Comparison operators (gt, gte, lt, lte) would allow integer lookups regardless of ALLOW_INT_LOOKUP setting.

    How to fix Access Restriction Bypass?

    Upgrade django-hashid-field to version 3.1.1 or higher.

    [,3.1.1)