CVE-2024-13301

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows ...

Continue Reading
CVE-2024-13301 OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) – Critical – Cross Site Scripting – SA-CONTRIB-2024-067

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows ...

Continue Reading
CVE-2024-13301 OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) – Critical – Cross Site Scripting – SA-CONTRIB-2024-067

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows ...

Continue Reading
WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account Takeover in github.com/h44z/wg-portal

WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account Takeover in github.com/h44z/wg-portal. NOTE: The source advisory for this report contains additional versions that could not be ...

Continue Reading
WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account Takeover

Impact Users of WireGuard Portal v2 who have OAuth (or OIDC) authentication backends enabled can be affected by an Account Takeover vulnerability if they visit a malicious website. Patches The problem ...

Continue Reading
WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account Takeover

Impact Users of WireGuard Portal v2 who have OAuth (or OIDC) authentication backends enabled can be affected by an Account Takeover vulnerability if they visit a malicious website. Patches The problem ...

Continue Reading
UBUNTU-CVE-2025-22376

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically...Read More ...

Continue Reading
Guzzle OAuth Subscriber has insufficient nonce entropy

Impact Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source (https://github.com/guzzle/oauth-subscriber/blob/0.8.0/src/Oauth1.php#L192). This can leave s ...

Continue Reading

Back to Main

Subscribe for the latest news: