yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
Moderate severity
GitHub Reviewed
Published
Dec 16, 2023
in
yiisoft/yii2-authclient
•
Updated Dec 22, 2023
Description
Published to the GitHub Advisory Database
Dec 18, 2023
Reviewed
Dec 18, 2023
Published by the National Vulnerability Database
Dec 22, 2023
Last updated
Dec 22, 2023
Impact
What kind of vulnerability is it? Who is impacted?
Original Report:
Patches
Has the problem been patched? What versions should users upgrade to?
2.2.15
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
not known yet.
References
Are there any links users can visit to find out more?
References