What kind of vulnerability is it? Who is impacted?
Original Report:
> The Oauth2 PKCE implementation is vulnerable in 2 ways:
> 1. The authCodeVerifier should be removed after usage (similar to 'authState')
> 2. There is a risk for a "downgrade attack" if PKCE is being relied on for CSRF protection.
Has the problem been patched? What versions should users upgrade to?
2.2.15
Is there a way for users to fix or remediate the vulnerability without upgrading?
not known yet.
Are there any links users can visit to find out more?
| Score | Percentile |
|---|---|
| 0.15% | 35.61% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 6.8 | 3.1 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-rw54-6826-c8j5 ↗ |
| CVE | CVE-2023-50714 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | yiisoft/yii2-authclient | < 2.2.15 | 2.2.15 | — |