Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mhc03

#31198de 53,635
8.2CVSS total
Vulnerabilidades · 1
PT-2023-25864
8.2
2023-07-06
Unknown · League/Oauth2-Server · CVE-2023-37260
**Name of the Vulnerable Software and Affected Versions** league/oauth2-server versions 8.3.2 through 8.5.2 **Description** The issue concerns an OAuth 2.0 authorization server written in PHP, where servers that passed their keys to the CryptKey constructor as a string instead of a file path would have the key included in a LogicException message if a valid pass phrase for the key was not provided. This has been patched so that the provided key is no longer exposed in the exception message. **Recommendations** For versions 8.3.2 through 8.5.2, upgrade to version 8.5.3 to receive the patch. As a temporary workaround for versions 8.3.2 through 8.5.2, pass the key as a file instead of a string.