HIGH7.5
GHSA-768m-5w34-2xf5
LTI 1.3 Tool Library's function used to generate random nonces not sufficiently cryptographically complex before v5.0
Quick fix
GHSA-768m-5w34-2xf5 — packbackbooks/lti-1-3-php-library: upgrade to the fixed version with the command below.
composer require packbackbooks/lti-1-3-php-library:^5.0Details
### Impact
The function used to generate random nonces was not sufficiently cryptographically complex. As a result values may be predictable and tokens may be forgable.
### Patches
Users should upgrade to version 5.0 immediately
### Workarounds
None.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/packbackbooks/lti-1-3-php-library
Introduced in:
0Fixed in: 5.0Fix
composer require packbackbooks/lti-1-3-php-library:^5.0References
- https://github.com/packbackbooks/lti-1-3-php-library/security/advisories/GHSA-768m-5w34-2xf5[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-31157[ADVISORY]
- https://github.com/packbackbooks/lti-1-3-php-library/commit/de19e8a0b28cdc7750fa3ca98471eeed26ba3e57[WEB]
- https://github.com/packbackbooks/lti-1-3-php-library[PACKAGE]
- https://openid.net/specs/openid-connect-core-1_0.html#IDToken[WEB]