Логотип exploitDog
bind:CVE-2017-18924
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-18924

Количество 2

Количество 2

nvd логотип

CVE-2017-18924

больше 5 лет назад

oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also therefore wouldn't describe this as a "vulnerability" with the library per se.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fw4-mgq9-39cx

почти 5 лет назад

Code Injection in oauth2-server

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-18924

oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also therefore wouldn't describe this as a "vulnerability" with the library per se.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-2fw4-mgq9-39cx

Code Injection in oauth2-server

CVSS3: 7.5
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу