VDB
Sign up
MEDIUM6.8

GHSA-rw54-6826-c8j5

yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable

Quick fix

GHSA-rw54-6826-c8j5 — yiisoft/yii2-authclient: upgrade to the fixed version with the command below.

composer require yiisoft/yii2-authclient:^2.2.15

Details

### Impact _What kind of vulnerability is it? Who is impacted?_

Original Report:

> The Oauth2 PKCE implementation is vulnerable in 2 ways: > 1. The `authCodeVerifier` should be removed after usage (similar to 'authState') > 2. There is a risk for a "downgrade attack" if PKCE is being relied on for CSRF protection.

### Patches _Has the problem been patched? What versions should users upgrade to?_

2.2.15

### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_

not known yet.

### References _Are there any links users can visit to find out more?_

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii2-authclient
Introduced in: 0Fixed in: 2.2.15
Fixcomposer require yiisoft/yii2-authclient:^2.2.15

References