1.2.2
8 months ago
6 days ago
Known vulnerabilities in the djust package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Exposure of Private Personal Information to an Unauthorized Actor in the serialization process. An attacker can obtain sensitive information, such as password hashes, privilege flags, tokens, and personally identifiable information, by accessing public view attributes that expose Django Model instances without a sensitive-field denylist. How to fix Exposure of Private Personal Information to an Unauthorized Actor? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the How to fix Authorization Bypass Through User-Controlled Key? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere through the How to fix Exposure of Resource to Wrong Sphere? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in the How to fix Improperly Controlled Modification of Dynamically-Determined Object Attributes? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Missing Authorization via the How to fix Missing Authorization? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the How to fix Cross-site Request Forgery (CSRF)? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Missing Authorization via the WebSocket/SSE mount path, where authorization checks are not properly enforced. An attacker can gain unauthorized access to sensitive views and perform privileged actions by connecting through WebSocket and bypassing standard authentication and permission checks. How to fix Missing Authorization? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Missing Authorization in the WebSocket/SSE path due to improper enforcement of tenant isolation. An attacker can access data belonging to other tenants by establishing a socket connection and issuing queries, resulting in unauthorized disclosure of sensitive information. How to fix Missing Authorization? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Missing Authorization inadequate enforcement of object-level permissions in the How to fix Missing Authorization? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the rendering of user-supplied URLs in How to fix Cross-site Scripting (XSS)? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in the How to fix Improperly Controlled Modification of Dynamically-Determined Object Attributes? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')? Upgrade | [,1.0.7) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of template filters and context variables. An attacker can inject and execute arbitrary client-side scripts by supplying crafted input that is rendered unescaped in the output. This can occur through various template constructs, including the use of filters such as How to fix Improper Encoding or Escaping of Output? Upgrade | [,1.1.1) |
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of context safety grants during template variable rebinding. An attacker can inject and execute arbitrary scripts by supplying crafted input that is assigned to a context variable previously marked as safe, which is then rebound in template constructs such as How to fix Improper Encoding or Escaping of Output? Upgrade | [,1.1.2) |