CVE-2023-50708

Published: Dic 22, 2023 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2023-3310 Aliases: GHSA-w8vh-p74j-x9xp
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,1
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: none
Integrity: high
Availability: none

Description

AI Translation Available

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 `state` and OpenID Connect `nonce` is vulnerable for a `timing attack` since it is compared via regular string comparison (instead of `Yii::$app->getSecurity()->compareString()`). Version 2.2.15 contains a patch for the issue. No known workarounds are available.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0016
Percentile
0,4th
Updated

EPSS Score Trend (Last 90 Days)

203

Observable Discrepancy

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Access Control
Potential Impacts:
Read Application Data Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Yii2-Authclient by Yiiframework

Version Range Affected
To 2.2.15 (exclusive)
cpe:2.3:a:yiiframework:yii2-authclient:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b5…
https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b5…
https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b5…
https://github.com/yiisoft/yii2-authclient/commit/dabddf2154ab7e7703740205a0692…
https://github.com/yiisoft/yii2-authclient/security/advisories/GHSA-w8vh-p74j-x…
https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b5…
https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b5…
https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b5…
https://github.com/yiisoft/yii2-authclient/commit/dabddf2154ab7e7703740205a0692…
https://github.com/yiisoft/yii2-authclient/security/advisories/GHSA-w8vh-p74j-x…