Описание
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| python-authlib | fixed | 1.7.0-1 | package | |
| python-authlib | fixed | 1.2.0-1+deb12u2 | bookworm | package |
| python-authlib | not-affected | bullseye | package |
Примечания
https://github.com/authlib/authlib/security/advisories/GHSA-jj8c-mmj3-mmgv
Fixed by: https://github.com/authlib/authlib/commit/401a7709c3fe43bce1b2105d16a475b688faa788 (v1.6.11)
Связанные уязвимости
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Authlib: Cross-site request forging when using cache