PT-2022-20573 · Unknown · Lti 1.3 Tool Library
Dbhynds
·
Published
2022-07-15
·
Updated
2023-07-24
·
CVE-2022-31158
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LTI 1.3 Tool Library versions prior to 5.0
Description
The issue concerns the Nonce Claim Value not being validated against the nonce value sent in the Authentication Request. This affects the LTI 1.3 Tool Library, a library used for building IMS-certified LTI 1.3 tool providers in PHP. There are currently no known workarounds.
Recommendations
For versions prior to 5.0, users should upgrade to version 5.0 to receive a patch.
As a temporary workaround, consider disabling the functionality that relies on the Nonce Claim Value until a patch is available.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lti 1.3 Tool Library