{ "id": "CVE-2024-22513", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-16T07:15:06.513", "lastModified": "2024-03-17T22:38:29.433", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method." }, { "lang": "es", "value": "Djangorestframework-simplejwt versi\u00f3n 5.3.1 y anteriores es vulnerable a la divulgaci\u00f3n de informaci\u00f3n. Un usuario puede acceder a los recursos de la aplicaci\u00f3n web incluso despu\u00e9s de que su cuenta haya sido deshabilitada debido a que faltan verificaciones de validaci\u00f3n del usuario a trav\u00e9s del m\u00e9todo for_user." } ], "metrics": {}, "references": [ { "url": "https://github.com/dmdhrumilmistry/CVEs/tree/main/CVE-2024-22513", "source": "cve@mitre.org" } ] }