CVE-2024-22513 Affecting python-djangorestframework-simplejwt package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.8% (52nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN14-PYTHONDJANGORESTFRAMEWORKSIMPLEJWT-11765691
  • published10 Aug 2025
  • disclosed16 Mar 2024

Introduced: 16 Mar 2024

CVE-2024-22513  (opens in a new tab)

How to fix?

There is no fixed version for Debian:14 python-djangorestframework-simplejwt.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python-djangorestframework-simplejwt package and not the python-djangorestframework-simplejwt package as distributed by Debian. See How to fix? for Debian:14 relevant fixed versions and status.

djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.

CVSS Base Scores

version 3.1