The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade social-auth-core to version 5.0.0 or higher.
social-auth-core is a package that makes Python social authentication simple.
Affected versions of this package are vulnerable to Authentication Bypass by Alternate Name via the get_user_id method in the Vend OAuth2 backend (social_core/backends/vend.py), where user identifiers are scoped only to a shop-local numeric ID rather than being namespaced by the shop's domain_prefix. Because two different Vend shops can issue the same numeric user ID, an attacker who controls an account on one shop can authenticate as an unrelated user on a different shop that shares the same numeric ID, bypassing account isolation and gaining full access to that user's account.