Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and ModelSelect2Widget can leak secret access tokens across requests. This can allow users to access restricted query sets and restricted data. This issue has been patched in version 8.4.1.
History

Tue, 27 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 May 2025 15:15:00 +0000

Type Values Removed Values Added
Description Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and ModelSelect2Widget can leak secret access tokens across requests. This can allow users to access restricted query sets and restricted data. This issue has been patched in version 8.4.1.
Title Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
Weaknesses CWE-402
CWE-918
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-27T15:03:10.062Z

Updated: 2025-05-27T15:17:02.957Z

Reserved: 2025-05-19T15:46:00.397Z

Link: CVE-2025-48383

cve-icon Vulnrichment

Updated: 2025-05-27T15:17:00.434Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-27T15:15:35.143

Modified: 2025-05-28T15:01:30.720

Link: CVE-2025-48383

cve-icon Redhat

No data.