PT-2024-40318 · Laravel · Laravel/Socialite

Published

2024-05-15

·

Updated

2024-05-15

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions laravel/socialite versions prior to 2.0.9
Description The issue concerns an insecure state generation mechanism in the OAuth authentication process, which poses security risks. This has been addressed by ensuring the state is generated using a truly random approach, thus enhancing the security of the OAuth flow.
Recommendations For versions prior to 2.0.9, update to version 2.0.9 to ensure the state is generated securely, enhancing the security of the OAuth flow.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-H97C-QP24-439V

Affected Products

Laravel/Socialite