Impact
djust, a Django extension, serializes entire Django Model instances to the client when assigned to a public view attribute. Because serialization lacked any denylist, sensitive fields such as password hashes, privilege flags, tokens and other personally identifiable information were transmitted to the browser. The flaw allows an attacker who can trigger such a view to gain knowledge of authentication credentials, elevate privileges, and expose private data, thereby compromising confidentiality and potentially integrity of user accounts.
Affected Systems
The vulnerability affects the djust library, specifically versions released before 1.0.7. Developers using djust in Django projects that expose Model instances in public view attributes are impacted. Any environment running djust 1.0.6 or earlier, regardless of Django version, is susceptible until patched to the fixed release.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by requesting any web page that renders a public view attribute containing a Model instance. As the serialization occurs server‑side and the data is sent to the client without filtering, the attack can be carried out remotely through normal HTTP requests to the affected view. The absence of a denylist means the entire object payload is exposed, making the attack highly effective if the view is publicly accessible.
OpenCVE Enrichment
Github GHSA