CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Oauth2 Server Project 1Oauth2 Server Sep 2, 2025 Mar 31, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0. |
1Oauth2 Server Project 1Oauth2 Server Nov 21, 2024 Aug 29, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a-zA-Z][a-zA-Z0-9+.-]+:"...Show more |
1Oauth2 Server Project 1Oauth2 Server Nov 21, 2024 Oct 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extens...Show more |