Impact
A vulnerability exists in the WebSocket handling of djust prior to version 1.0.7 where the server rebuilds an HTTP request without including the original client Host. The resulting request defaults to the string "testserver", causing tenant resolution mechanisms that rely on host or subdomain to misidentify the tenant. When tenant resolution fails, the application either returns an empty dataset (broken tenancy) or, if configuration permits, returns unscoped data from other tenants (cross‑tenant disclosure). The flaw therefore directly violates confidentiality and may also impact integrity and availability of data segregation.
Affected Systems
The affected product is djust made by djust‑org. All releases before 1.0.7 are vulnerable, including 1.0.6 and earlier editions. Updating to 1.0.7 or later is required to receive the fix.
Risk and Exploitability
The CVSS score of 6.3 classifies the issue as moderate. The EPSS score falls below 1 %, suggesting exploitation is unlikely yet still possible, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by initiating a WebSocket connection to the live path and relying on the host omission to obtain data from a different tenant or to break tenant isolation. The fix now validates the handshake Host against ALLOWED_HOSTS and propagates it to the reconstructed request, matching live‑path tenant resolution to HTTP. The risk is heightened when STRICT_MODE is disabled, which would allow cross‑tenant data leakage for any existing connections.
OpenCVE Enrichment
Github GHSA