The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reb ...
Continue ReadingMay 22, 2025
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reb ...
Continue ReadingMay 22, 2025
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a...Read More ...
Continue ReadingMay 22, 2025
oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states ...
Continue ReadingMay 22, 2025
oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states ...
Continue ReadingMay 22, 2025
Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent...Read More ...
Continue ReadingMay 22, 2025
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a...Read More ...
Continue ReadingMay 22, 2025
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a...Read More ...
Continue ReadingMay 22, 2025
Back to Main