Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Edevilo

#30100de 53,622
8.7CVSS total
Vulnerabilidades · 1
PT-2014-2777
8.7
2014-05-20
Simplegeo · Python-Oauth2 · CVE-2013-4346
**Name of the Vulnerable Software and Affected Versions** SimpleGeo python-oauth2 (affected versions not specified) **Description** The issue is related to the Server.verify request function in SimpleGeo python-oauth2, which does not check the nonce. This omission allows remote attackers to perform replay attacks via a signed URL. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.