Improper Input Validation Affecting django-oauth-toolkit package, versions [, 0.8.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-DJANGOOAUTHTOOLKIT-1082326
- published 4 Mar 2021
- disclosed 4 Mar 2021
- credit Unknown
How to fix?
Upgrade django-oauth-toolkit
to version 0.8.0 or higher.
Overview
django-oauth-toolkit is an OAuth2 Provider for Django
Affected versions of this package are vulnerable to Improper Input Validation. Multiple issues exist in the way Django-oauth-toolkit
provides validation for 'Basic' authentication.
References
CVSS Scores
version 3.1