QID 997508
Date Published: 2024-02-26
QID 997508: Python (Pip) Security Update for oauth2 (GHSA-4433-4cxq-vv73)
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL. The vulnerability does not appear to be patched according to the following discussion.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4433-4cxq-vv73 for updates and patch information.
Vendor References
- GHSA-4433-4cxq-vv73 -
github.com/advisories/GHSA-4433-4cxq-vv73
CVEs related to QID 997508
Software Advisories
| Advisory ID | Software | Component | Link |
|---|