Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33203
HistoryDec 08, 2021 - 4:35 a.m.

Authorization Bypass

2021-12-0804:35:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
django
authorization
bypass
vulnerability
regex
resolvers
url paths
access control

EPSS

0.001

Percentile

48.7%

Django is vulnerable to authorization bypass. The vulnerability exists due to the insecure regex used for the match path names, allowing an attacker to bypass the upstream access control based on URL paths through the match function in resolvers.py