Skip to content

yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable

Moderate severity GitHub Reviewed Published Dec 16, 2023 in yiisoft/yii2-authclient • Updated Dec 22, 2023

Package

composer yiisoft/yii2-authclient (Composer)

Affected versions

< 2.2.15

Patched versions

2.2.15

Description

Impact

What kind of vulnerability is it? Who is impacted?

Original Report:

The Oauth2 PKCE implementation is vulnerable in 2 ways:

  1. The authCodeVerifier should be removed after usage (similar to 'authState')
  2. There is a risk for a "downgrade attack" if PKCE is being relied on for CSRF protection.

Patches

Has the problem been patched? What versions should users upgrade to?

2.2.15

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

not known yet.

References

Are there any links users can visit to find out more?

References

@samdark samdark published to yiisoft/yii2-authclient Dec 16, 2023
Published to the GitHub Advisory Database Dec 18, 2023
Reviewed Dec 18, 2023
Published by the National Vulnerability Database Dec 22, 2023
Last updated Dec 22, 2023

Severity

Moderate
6.8
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

CVE ID

CVE-2023-50714

GHSA ID

GHSA-rw54-6826-c8j5

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.