oauth4webapi is vulnerable to Authentication Bypass by Capture-replay
15
Low Risk
Affected versions of the oauth4webapi library are vulnerable to authentication bypass by capture-replay because the DPoP (demonstrating proof of possession) iat (issued at) timestamp is not checked. This flaw allows a malicious user to sniff network traffic and bypass authentication by replaying the captured message to the server, achieving the same effect as the original request (or with minimal changes).
You are affected if you are using a version that falls within the vulnerable range.
oauth4webapi is vulnerable to Authentication Bypass by Capture-replay in versions 2.8.0 - 2.8.0.
Upgrade the oauth4webapi library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant