Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25870
HistoryJul 13, 2020 - 5:26 a.m.

Improper Authorization

2020-07-1305:26:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.007 Low

EPSS

Percentile

79.8%

Google OAuth Client is vulnerable to improper authorization. Due to a flaw in implementation for Proof Key for Code Exchange (PKCE), the code sent by authorization server is not properly handled to authorize the client that issued the initial authorization request, allowing an attacker with a malicious application on the client-side to gain authorization to the protected resource.