GHSA-rw54-6826-c8j5
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
Quick fix
GHSA-rw54-6826-c8j5 — yiisoft/yii2-authclient: upgrade to the fixed version with the command below.
composer require yiisoft/yii2-authclient:^2.2.15Details
### Impact _What kind of vulnerability is it? Who is impacted?_
Original Report:
> The Oauth2 PKCE implementation is vulnerable in 2 ways: > 1. The `authCodeVerifier` should be removed after usage (similar to 'authState') > 2. There is a risk for a "downgrade attack" if PKCE is being relied on for CSRF protection.
### Patches _Has the problem been patched? What versions should users upgrade to?_
2.2.15
### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_
not known yet.
### References _Are there any links users can visit to find out more?_
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.2.15composer require yiisoft/yii2-authclient:^2.2.15References
- https://github.com/yiisoft/yii2-authclient/security/advisories/GHSA-rw54-6826-c8j5[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-50714[ADVISORY]
- https://github.com/yiisoft/yii2-authclient/commit/721ed974bc44137437b0cdc8454e137fff8db213[WEB]
- https://github.com/yiisoft/yii2-authclient[PACKAGE]
- https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OAuth1.php#L158[WEB]
- https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OAuth2.php#L121[WEB]
- https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OpenIdConnect.php#L420[WEB]