PT-2022-20573 · Unknown · Lti 1.3 Tool Library

Dbhynds

·

Published

2022-07-15

·

Updated

2023-07-24

·

CVE-2022-31158

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions LTI 1.3 Tool Library versions prior to 5.0
Description The issue concerns the Nonce Claim Value not being validated against the nonce value sent in the Authentication Request. This affects the LTI 1.3 Tool Library, a library used for building IMS-certified LTI 1.3 tool providers in PHP. There are currently no known workarounds.
Recommendations For versions prior to 5.0, users should upgrade to version 5.0 to receive a patch. As a temporary workaround, consider disabling the functionality that relies on the Nonce Claim Value until a patch is available.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2022-31158
GHSA-5P73-QG2V-383H

Affected Products

Lti 1.3 Tool Library