djust@0.9.0

Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

  • latest version

    1.2.2

  • latest non vulnerable version

  • first published

    8 months ago

  • latest version published

    6 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the djust package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Missing Authentication for Critical Function

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Missing Authentication for Critical Function through the handle_event process. An attacker can execute unauthorized event handler methods by maintaining an open WebSocket connection after receiving a redirect frame, thereby bypassing authentication and authorization checks. This is only exploitable if a non-browser WebSocket client is used and the attacker knows or can enumerate the view path and event names.

    How to fix Missing Authentication for Critical Function?

    Upgrade djust to version 1.0.4 or higher.

    [,1.0.4)
    • H
    Exposure of Private Personal Information to an Unauthorized Actor

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Exposure of Private Personal Information to an Unauthorized Actor in the serialization process. An attacker can obtain sensitive information, such as password hashes, privilege flags, tokens, and personally identifiable information, by accessing public view attributes that expose Django Model instances without a sensitive-field denylist.

    How to fix Exposure of Private Personal Information to an Unauthorized Actor?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • M
    Authorization Bypass Through User-Controlled Key

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the handle_mount and ViewRuntime._build_request processes when a reconstructed request omits the client Host, leading to incorrect tenant resolution on the live path. An attacker can access data from other tenants by exploiting this misconfiguration, especially when STRICT_MODE is set to False. This is only exploitable if STRICT_MODE=False is configured.

    How to fix Authorization Bypass Through User-Controlled Key?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • C
    Exposure of Resource to Wrong Sphere

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere through the eval_handler process. An attacker can access live application state and execute remote method invocations by sending requests to network-exposed observability endpoints when the application is running with DEBUG enabled and the localhost restriction middleware is not installed. This is only exploitable if DEBUG is enabled and the localhost restriction middleware is omitted from the configuration.

    How to fix Exposure of Resource to Wrong Sphere?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • H
    Improperly Controlled Modification of Dynamically-Determined Object Attributes

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in the state_json process. An attacker can escalate privileges or tamper with sensitive view attributes by modifying the unsigned snapshot data and submitting it during a reconnect.

    How to fix Improperly Controlled Modification of Dynamically-Determined Object Attributes?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • C
    Missing Authorization

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Missing Authorization via the session_id parameter. An attacker can gain unauthorized access to another user's session by obtaining or guessing a valid session_id and connecting to the message endpoint, allowing them to execute actions with the victim's identity and state.

    How to fix Missing Authorization?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • M
    Cross-site Request Forgery (CSRF)

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the session_id parameter and lack of Origin validation in the Server-Sent-Events endpoints. An attacker can perform unauthorized actions as an authenticated user by tricking a victim into visiting a malicious site that initiates requests to the vulnerable endpoints using the victim's credentials.

    How to fix Cross-site Request Forgery (CSRF)?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • M
    Missing Authorization

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Missing Authorization via the WebSocket/SSE mount path, where authorization checks are not properly enforced. An attacker can gain unauthorized access to sensitive views and perform privileged actions by connecting through WebSocket and bypassing standard authentication and permission checks.

    How to fix Missing Authorization?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • M
    Missing Authorization

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Missing Authorization in the WebSocket/SSE path due to improper enforcement of tenant isolation. An attacker can access data belonging to other tenants by establishing a socket connection and issuing queries, resulting in unauthorized disclosure of sensitive information.

    How to fix Missing Authorization?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • M
    Missing Authorization

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Missing Authorization inadequate enforcement of object-level permissions in the get_object process. An attacker can gain unauthorized access to sensitive information or perform unauthorized actions on objects by directly loading pages, navigating via SPA url changes, or embedding views as child components.

    How to fix Missing Authorization?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • M
    Cross-site Scripting (XSS)

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the rendering of user-supplied URLs in href or action attributes within built-in component template tags without validating the URL scheme. An attacker can execute arbitrary JavaScript in the victim's browser by supplying a crafted javascript: URL, which is rendered verbatim and executed when clicked by a user. This is only exploitable if a developer passes user-controllable URLs to the affected component tags without proper scheme validation.

    How to fix Cross-site Scripting (XSS)?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • H
    Improperly Controlled Modification of Dynamically-Determined Object Attributes

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in the update_model process. An attacker can manipulate sensitive view attributes by sending crafted events with arbitrary field names and values over the WebSocket interface. This can result in unauthorized modification of business logic or authorization state, especially when public view attributes are used to store such information. Type coercion of values to match attribute types further facilitates exploitation.

    How to fix Improperly Controlled Modification of Dynamically-Determined Object Attributes?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • H
    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the handle_mount process in the WebSocket and SSE view-mount path. An attacker can trigger execution of arbitrary importable modules' top-level code by sending a crafted frame specifying a module path, leading to server-side code execution, denial of service through import bombs or expensive dependency trees, and information disclosure via error messages.

    How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')?

    Upgrade djust to version 1.0.7 or higher.

    [,1.0.7)
    • M
    Improper Encoding or Escaping of Output

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of template filters and context variables. An attacker can inject and execute arbitrary client-side scripts by supplying crafted input that is rendered unescaped in the output. This can occur through various template constructs, including the use of filters such as linenumbers, escape, unordered_list, safeseq, linebreaks, and the render_slot tag, as well as by reusing context variables previously marked as safe. No special configuration is required for exploitation.

    How to fix Improper Encoding or Escaping of Output?

    Upgrade djust to version 1.1.1 or higher.

    [,1.1.1)
    • H
    Improper Encoding or Escaping of Output

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of context safety grants during template variable rebinding. An attacker can inject and execute arbitrary scripts by supplying crafted input that is assigned to a context variable previously marked as safe, which is then rebound in template constructs such as {% with %}, {% for %}, {% include ... with %}, or assign tags. This can occur without the use of filter chains or the |safe filter anywhere in the template.

    How to fix Improper Encoding or Escaping of Output?

    Upgrade djust to version 1.1.2 or higher.

    [,1.1.2)