Code Injection in oauth2-server
High severity
GitHub Reviewed
Published
Apr 22, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Oct 4, 2020
Reviewed
Apr 21, 2021
Published to the GitHub Advisory Database
Apr 22, 2021
Last updated
Feb 1, 2023
"oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also therefore wouldn't describe this as a "vulnerability" with the library per se.'"
References