DRUPAL-CONTRIB-2024-067

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/miniorange_oauth_client/DRUPAL-CONTRIB-2024-067.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2024-067
Aliases
Published
2024-12-04T14:40:50Z
Modified
2026-09-10T03:46:09Z
Summary
[none]
Details

This module enables you to authenticate users through an Identity Provider (IdP) or OAuth Server, allowing them to log in to your Drupal site.

The module does not sufficiently escape query parameters sent to the callback URL when displaying error messages, particularly if the code parameter is missing in the response.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/miniorange_oauth_client

Package

Name
drupal/miniorange_oauth_client
Purl
pkg:composer/drupal/miniorange_oauth_client?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.32.0
Fixed
3.44.0
Database specific
Show details
{
    "constraint": ">=3.32.0 <3.44.0"
}
Type
ECOSYSTEM
Events
Introduced
4.0.1
Fixed
4.0.19
Database specific
Show details
{
    "constraint": ">=4.0.1 <4.0.19"
}

Database specific

affected_versions
">=3.32.0 <3.44.0 || >=4.0.1 <4.0.19"
patched
true
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/miniorange_oauth_client/DRUPAL-CONTRIB-2024-067.json"