VDB
Sign up
HIGH7.1

GHSA-c7c5-5j6r-q957

djust has broken object-level access control (IDOR)

Quick fix

GHSA-c7c5-5j6r-q957 — djust: upgrade to the fixed version with the command below.

pip install --upgrade 'djust>=1.0.7'

Details

### Impact djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket **mount** and **event** paths but **not** on three other render entry points: (a) the initial **HTTP GET** render, (b) **SPA `url_change`** navigation, and (c) `{% live_render %}` **embedded child** views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-change, or composing it as an embedded child — a classic IDOR / broken object-level access control on object-scoped views.

### Patches Fixed in **djust 1.0.7**. All render entry points now route through a shared `enforce_object_permission` chokepoint: HTTP GET returns **403**, `url_change` emits a `permission_denied` frame and skips the render, and `{% live_render %}` (eager + lazy) refuses the embed. Views without a custom `get_object` are unaffected (no-op).

### Workarounds No reliable workaround short of upgrading. Do not expose object-scoped views through the HTTP-GET / url_change / live_render paths until patched.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/djust
Introduced in: 0Fixed in: 1.0.7
Fixpip install --upgrade 'djust>=1.0.7'

References