PT-2026-105800 · Pypi · Djust
Publicado
2026-10-01
·
Atualizado
2026-10-01
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Impact
SSE sessions were keyed solely by a client-chosen
session id with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a session id could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state.Patches
Fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal.
Workarounds
Disable the SSE transport short of upgrading.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Djust