VDB
Sign up
—

PYSEC-2019-20

Quick fix

PYSEC-2019-20 — django-rest-registration: upgrade to the fixed version with the command below.

pip install --upgrade 'django-rest-registration>=0.5.0'

Details

verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a security-critical function with an incorrect argument.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django-rest-registration
Introduced in: 0Fixed in: 0.5.0
Fixpip install --upgrade 'django-rest-registration>=0.5.0'

References