Impact
What kind of vulnerability is it? Who is impacted?
Original Report:
The Oauth2 PKCE implementation is vulnerable in 2 ways:
- The
authCodeVerifier
should be removed after usage (similar to 'authState')
- There is a risk for a "downgrade attack" if PKCE is being relied on for CSRF protection.
Patches
Has the problem been patched? What versions should users upgrade to?
TBD
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
not known yet.
References
Are there any links users can visit to find out more?
Impact
What kind of vulnerability is it? Who is impacted?
Original Report:
Patches
Has the problem been patched? What versions should users upgrade to?
TBD
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
not known yet.
References
Are there any links users can visit to find out more?