geex-arts django-jet
- <= 1.0.8
An authorization vulnerability has been identified in Geex-Arts Django-Jet versions up to 1.0.8. The issue resides in the OAuth Credential Revoke Handler, where missing authorization allows for unauthorized revocation of credentials. This vulnerability can be exploited remotely, and a public exploit is available.
Exploitation of this vulnerability allows for unauthorized revocation of OAuth credentials, potentially disrupting integrations with third-party services.
The vulnerability can be reproduced by sending a GET request to the OAuth credential revoke endpoint for Google Analytics or Yandex Metrika, using a module primary key that does not belong to the user. The request can be made without authentication or ownership checks, bypassing necessary authorization requirements.
Users are advised to update to a version of Geex-Arts Django-Jet that addresses this vulnerability. Consult the project's GitHub repository for the latest release information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.