Lucene search

K
cveGitHub_MCVE-2023-50708
HistoryDec 22, 2023 - 7:15 p.m.

CVE-2023-50708

2023-12-2219:15:08
CWE-203
GitHub_M
web.nvd.nist.gov
18
yii2-authclient
openid
oauth
oauth2
openid connect
timing attack
security vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

26.9%

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 state and OpenID Connect nonce is vulnerable for a timing attack since it is compared via regular string comparison (instead of Yii::$app->getSecurity()->compareString()). Version 2.2.15 contains a patch for the issue. No known workarounds are available.

Affected configurations

Nvd
Vulners
Node
yiiframeworkyii2-authclientRange<2.2.15
VendorProductVersionCPE
yiiframeworkyii2-authclient*cpe:2.3:a:yiiframework:yii2-authclient:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "yiisoft",
    "product": "yii2-authclient",
    "versions": [
      {
        "version": "< 2.2.15",
        "status": "affected"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

26.9%

Related for CVE-2023-50708